GitHub Actions package intelligence

tj-actions/changed-files Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the GitHub Actions package tj-actions/changed-files, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting tj-actions/changed-files
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
tj-actions/changed-files KEVs with sensor-observed exploitation activity

Review tj-actions/changed-files exploitation against the versions you run

All one exploited tj-actions/changed-files vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested tj-actions/changed-files vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2025-30066

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected...

In CISA 18 Mar 2025

Recurring weakness patterns

Embedded Malicious Code account for mapped occurrences across this tj-actions/changed-files KEV portfolio.

Browse all KEVs →