SB2025032501 - Backdoor in reviewdog



SB2025032501 - Backdoor in reviewdog

Published: March 25, 2025

Security Bulletin ID SB2025032501
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Embedded malicious code (backdoor) (CVE-ID: CVE-2025-30154)

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The reviewdog/action-setup@v1 repository was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added to it. Purpose of the malicious code was to dumps exposed secrets to Github Actions Workflow Logs.

Other reviewdog actions that use reviewdog/action-setup@v1 would also be compromised, regardless of version or pinning method:

  • reviewdog/action-shellcheck
  • reviewdog/action-composite-template
  • reviewdog/action-staticcheck
  • reviewdog/action-ast-grep
  • reviewdog/action-typos



Remediation

Install update from vendor's website.