{"id":"GHSA-qmg3-hpqr-gqvc","summary":"Multiple Reviewdog actions were compromised during a specific time period","details":"### Summary\n\n`reviewdog/action-setup@v1` was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.\n\nOther reviewdog actions that use `reviewdog/action-setup@v1` would also be compromised, regardless of version or pinning method:\n- reviewdog/action-shellcheck\n- reviewdog/action-composite-template\n- reviewdog/action-staticcheck\n- reviewdog/action-ast-grep\n- reviewdog/action-typos\n\n### Details\n\nMalicious commit: https://github.com/reviewdog/action-setup/commit/f0d342d\nfix/retag via version upgrade: https://github.com/reviewdog/action-setup/commit/3f401fe\n\nSee the detailed report from Wiz Research: [Wiz Blog Post](https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup) and reviewdog maintainer annoucement: [reviewdog #2079](https://github.com/reviewdog/reviewdog/issues/2079)","aliases":["CVE-2025-30154"],"modified":"2025-10-22T19:29:23Z","published":"2025-03-19T15:19:12Z","database_specific":{"cwe_ids":["CWE-506"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-03-19T15:19:12Z","nvd_published_at":"2025-03-19T16:15:33Z"},"references":[{"type":"WEB","url":"https://github.com/reviewdog/reviewdog/security/advisories/GHSA-qmg3-hpqr-gqvc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30154"},{"type":"WEB","url":"https://github.com/reviewdog/reviewdog/issues/2079"},{"type":"WEB","url":"https://github.com/reviewdog/action-setup/commit/3f401fe1d58fe77e10d665ab713057375e39b887"},{"type":"WEB","url":"https://github.com/reviewdog/action-setup/commit/f0d342d24037bb11d26b9bd8496e0808ba32e9ec"},{"type":"PACKAGE","url":"https://github.com/reviewdog/reviewdog"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30154"},{"type":"WEB","url":"https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup"}],"affected":[{"package":{"name":"reviewdog/action-setup","ecosystem":"GitHub Actions"},"versions":["1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-qmg3-hpqr-gqvc/GHSA-qmg3-hpqr-gqvc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:H"}]}