Unencrypted API Key Storage Vulnerability in Jenkins Curseforge Publisher Plugin
CVE-2025-64146
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 October 2025
What is CVE-2025-64146?
The Curseforge Publisher Plugin for Jenkins improperly stores API keys in an unencrypted format within job configuration files on the Jenkins controller. This flaw enables users with Item or Extended Read permissions, as well as those with access to the Jenkins file system, to potentially view sensitive API credentials. It's crucial for users of this plugin to take immediate measures to secure their Jenkins environments, including reviewing access permissions and implementing encryption for sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Curseforge Publisher Plugin 0 <= 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved