CVE-2025-52493 is a medium-severity information exposure vulnerability in PagerDuty Runbook affecting versions through 2025-06-12. On the /config/index configuration page, the application returned full stored secret values to the client and embedded them directly in HTML password input fields in the DOM. Although the UI masked these values visually using <input type="password">, the underlying cleartext secrets remained present in the page source and could be revealed trivially by an authenticated administrative user changing the field type from "password" to "text" in browser developer tools. Exposed values could include API keys, service account credentials, and other sensitive tokens for integrated systems. The flaw stems from relying on client-side masking for protection rather than preventing secret material from being sent to the browser at all.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A medium-severity information disclosure issue in PagerDuty Cloud Runbook where stored secrets (API keys, service account credentials, tokens) were delivered in cleartext to the browser DOM and merely masked by password-field rendering, enabling authenticated admins to trivially reveal and copy the secrets via browser developer tools.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.