VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
Summary
| CVE | CVE-2026-13380 |
|---|---|
| State | PUBLISHED |
| Assigner | SRA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-20 21:16:46 UTC |
| Updated | 2026-07-21 18:16:55 UTC |
| Description | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server. |
Risk And Classification
Primary CVSS: v4.0 9 CRITICAL from 57dba5dd-1a03-47f6-8b36-e84e47d335d8
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002620000 probability, percentile 0.177610000 (date 2026-07-21)
Problem Types: CWE-201 | CWE-312 | CWE-201 CWE-201 Insertion of sensitive information into sent data | CWE-312 CWE-312 Cleartext storage of sensitive information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 57dba5dd-1a03-47f6-8b36-e84e47d335d8 | Secondary | 9 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vsee.com/clinic | 57dba5dd-1a03-47f6-8b36-e84e47d335d8 | vsee.com | |
| labs.sra.io/posts/vseeclinic | 57dba5dd-1a03-47f6-8b36-e84e47d335d8 | labs.sra.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Chris Jones (SRA) (en)
CNA: Drew Young (SRA) (en)
CNA: Maguire Younes (SRA) (en)
There are currently no legacy QID mappings associated with this CVE.