CVE-2025-52493
Last modified
CVE-2025-52493 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pagerduty | Runbook Automation | <= 2025-06-12 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-52493?
How severe is CVE-2025-52493?
How do I fix CVE-2025-52493?
Are you affected by CVE-2025-52493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
