The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on Tuesday about a security vulnerability related to the supply chain breach affecting GitHub Action, specifically the tj-actions/changed-files repository, which has been included in its Known Exploited Vulnerabilities (KEV) list.
This critical vulnerability, identified as CVE-2025-30066 (CVSS score: 8.6), concerns the unauthorized access of the GitHub Action to insert malicious code that allows for remote execution.
This critical vulnerability, identified as CVE-2025-30066 (CVSS score: 8.6), concerns the unauthorized access of the GitHub Action to insert malicious code that allows for remote execution.
