CVE-2026-13380 Details
Description
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
A vulnerability exists in VSee Clinic version 7.1.26 and VSee Clinic API version 1.3.0, where cleartext SFTP credentials are exposed in the HTTP responses of three unauthenticated endpoints. This issue arises only when SFTP connections are configured within the application. An unauthenticated remote attacker can intercept these HTTP responses and obtain the SFTP credentials, which can then be used to access the corresponding SFTP server.
Users can update VSee Clinic to version 7.1.26.1 or later and VSee Clinic API to version 1.3.0.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.sra.io/posts/vseeclinic | Security Risk Advisors | Third Party Advisory |
| https://vsee.com/clinic | Security Risk Advisors | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | Security Risk Advisors |
| CWE-312 | Cleartext Storage of Sensitive Information | Security Risk Advisors |
Affected Products
| Product | Versions |
|---|---|
| vsee clinic | 7.1.26 |
CPE
Remediation
| |
| vsee clinic api | 1.3.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | Initial Analysis | [email protected] |
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | Security Risk Advisors |