Insecure Direct Object Reference in VSee Clinic by VSee
CVE-2026-13381

8.7HIGH

Key Information:

Vendor

Vsee

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-13381?

VSee Clinic versions 7.1.26 and API 1.3.0 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability present in the /v1.3.0/api/files endpoint. This flaw allows an authenticated attacker to manipulate the 'remark' request parameter, enabling them to enumerate, access, and potentially delete files that belong to other users on the application server. This vulnerability poses a significant risk as it compromises user data privacy and application integrity.

Affected Version(s)

Clinic 7.1.26 < 7.1.26.1

Clinic 1.3.0 < 1.3.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chris Jones (SRA)
Drew Young (SRA)
Maguire Younes (SRA)
.