CVE
CVE-2025-30154
- First Reported
- Aug 17, 2026
- Latest Reported
- Aug 17, 2026
Reported Context (1)
- Cybersecurity and Infrastructure Security Agency (2025) Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154). How Developer Dependency Culture Became a Major Software Supply-Chain Attack Surface
CVE (2)
Malware (3)
People (2)
Threat Actors (3)
MITRE ATT&CK (2)
Vendors (4)
Products (8)
Tools (1)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.