Gnome-boxes writes passwords in clear text during box creation.
When creating a new box with an OS that supports express install a kickstart (RHEL/Fedora) script or preseed.cfg (Debian) file is written in the [user]/.cache/gnome-boxes/ directory that contains the clear text password for root and any users defined during install. Also, the files are not deleted after the install is completed. When anaconda generates kickstart scripts during an OS install the passwords are encrypted.
Edited by Ghost User