← All CVEs

CVE-2025-30154

high · 8.6Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2025-03-24Remediation due 2025-04-14

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

8.6
CVSS
2.4%
EPSS (exploit prob.)
84th
EPSS percentile
2025-03-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CWE-506

Affected products

VendorProductAffected versions
reviewdogaction-ast-grep< 1.26.2
reviewdogaction-composite-template< 0.20.2
reviewdogaction-setup1
reviewdogaction-shellcheck< 1.29.2
reviewdogaction-staticcheck< 1.26.2
reviewdogaction-typos< 1.17.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-30154