🔐 CVE Alert

CVE-2026-13381

UNKNOWN 0.0

VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.

CWE CWE-639
Vendor vsee
Product clinic
Published Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for vsee clinic

Be the first to know when new unknown vulnerabilities affecting vsee clinic are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

VSee / Clinic
7.1.26 < 7.1.26.1
VSee / Clinic
1.3.0 < 1.3.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
labs.sra.io: https://labs.sra.io/posts/vseeclinic vsee.com: https://vsee.com/clinic

Credits

Chris Jones (SRA) Drew Young (SRA) Maguire Younes (SRA)