{"id":"CVE-2025-30154","summary":"Multiple Reviewdog actions were compromised during a specific time period","details":"reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.","aliases":["GHSA-qmg3-hpqr-gqvc"],"modified":"2026-08-12T03:51:37.751315568Z","published":"2025-03-19T15:15:29.113Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30154.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-506"]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30154"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30154.json"},{"type":"ADVISORY","url":"https://github.com/reviewdog/reviewdog/security/advisories/GHSA-qmg3-hpqr-gqvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30154"},{"type":"REPORT","url":"https://github.com/reviewdog/reviewdog/issues/2079"},{"type":"FIX","url":"https://github.com/reviewdog/action-setup/commit/3f401fe1d58fe77e10d665ab713057375e39b887"},{"type":"FIX","url":"https://github.com/reviewdog/action-setup/commit/f0d342d24037bb11d26b9bd8496e0808ba32e9ec"},{"type":"ARTICLE","url":"https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/reviewdog/action-ast-grep","events":[{"introduced":"0"},{"fixed":"5139a664d8891a080f67b78c6e6e85ccb2e002f6"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:reviewdog:action-ast-grep:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.26.2"}]}},{"type":"GIT","repo":"https://github.com/reviewdog/action-composite-template","events":[{"introduced":"0"},{"fixed":"e8f0e0a5f62a05a6d9e4bd84c4b6e582b8091e23"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.20.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:reviewdog:action-composite-template:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/reviewdog/action-setup","events":[{"introduced":"d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f"},{"fixed":"3f401fe1d58fe77e10d665ab713057375e39b887"},{"fixed":"f0d342d24037bb11d26b9bd8496e0808ba32e9ec"}],"database_specific":{"cpe":"cpe:2.3:a:reviewdog:action-setup:1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1"},{"last_affected":"1"}],"source":["CPE_STRING","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/reviewdog/action-shellcheck","events":[{"introduced":"0"},{"fixed":"1081fc2953db00c6756f750e09563b49a8a09408"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:reviewdog:action-shellcheck:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.29.2"}]}},{"type":"GIT","repo":"https://github.com/reviewdog/action-staticcheck","events":[{"introduced":"0"},{"fixed":"f106cde0d7fe94c0eeb49352ee7ba9b19c7021d1"}],"database_specific":{"cpe":"cpe:2.3:a:reviewdog:action-staticcheck:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.26.2"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/reviewdog/action-typos","events":[{"introduced":"0"},{"fixed":"627388e238f182b925d9acd151432f9b68f1d666"}],"database_specific":{"cpe":"cpe:2.3:a:reviewdog:action-typos:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.17.2"}],"source":"CPE_RANGE"}}],"versions":["1","= 1","v1.26.1","v1.26.0","v1.25.0","v1.25","v1.24.0","v1.24","v1.23.0","v1.23","v1.22.0","v1.22","v1.21.0","v1.21","v1.20.0","v1.20","v1.19.0","v1.19","v1.18.0","v1.18","v1.17.0","v1.17","v1.16.0","v1.16","v1.15.0","v1.15","v1.14.0","v1.14","v1.13.0","v1.13","v1.12.0","v1.12","v1.11.0","v1.11","v1.10.0","v1.10","v1.9.0","v1.9","v1.8.0","v1.8","v1.7.0","v1.7","v1.6.0","v1.6","v1.5.0","v1.5","v1.4.0","v1.4","v1.3.0","v1.3","v1.2.0","v1.2","v1.1.0","v1.1","v1.0.2","v1.0","v1.0.1","v1.0.0","v0.20.1","v0.20.0","v0.19.0","v0.19","v0.18.0","v0.18","v0.17.0","v0.17","v0.16.0","v0.16","v0.15.0","v0.15","v0.14.0","v0.14","v0.13.0","v0.13","v0.12.0","v0.12","v0.11.0","v0.11","v0.10.0","v0.10","v0.9.0","v0.9","v0.8.1","v0.8","v0.8.0","v0.7.1","v0.7","v0.7.0","v0.6.0","v0.6","v0.5.0","v0.5","v0.4.0","v0.4","v0.3.2","v0.3","v0.3.1","v0.3.0","v0.2.0","v0.2","v0.1.1","v0.1","v0.1.0","v1.29.1","v1.29.0","v1.28.0","v1.28","v1.27.0","v1.27","v1.26","v1.18.1","v1.16.1","v1.11.1","v1.8.1","v1.2.1","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.22.2","v1.22.1","v1.18.2","v1.15.1","v1.11.2","v1.10.2","v1.10.1","v1.9.1","v1.4.3","v1.4.2","v1.4.1","v1.17.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30154.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}