CVE-2025-53650: Jenkins Credentials Binding

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

Affected products

  • Jenkins Credentials Binding: up to and including 687.689.v1a_f775332fc

Published 2025-07-09. Last modified 2026-06-17.