CVE-2025-30154: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

High severity, CVSS 8.6. Actively exploited: in CISA KEV since 2025-03-24. EPSS: 2.4% chance of exploitation in the next 30 days.

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

Affected products

  • reviewdog Action-Ast-Grep: before 1.26.2 (fixed in 1.26.2)
  • reviewdog Action-Composite-Template: before 0.20.2 (fixed in 0.20.2)
  • reviewdog Action-Setup: version 1 only
  • reviewdog Action-Shellcheck: before 1.29.2 (fixed in 1.29.2)
  • reviewdog Action-Staticcheck: before 1.26.2 (fixed in 1.26.2)
  • reviewdog Action-Typos: before 1.17.2 (fixed in 1.17.2)

Published 2025-03-19. Last modified 2026-06-17.