CVE-2026-13381
VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.
| CWE | CWE-639 |
| Vendor | vsee |
| Product | clinic |
| Published | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for vsee clinic
Be the first to know when new unknown vulnerabilities affecting vsee clinic are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
VSee / Clinic
7.1.26 < 7.1.26.1
VSee / Clinic
1.3.0 < 1.3.0.1
References
Credits
Chris Jones (SRA) Drew Young (SRA) Maguire Younes (SRA)