CVE-2026-13380

N/A Unknown
Published: July 20, 2026 Modified: July 20, 2026
View on NVD

Description

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://labs.sra.io/posts/vseeclinic
Source: 57dba5dd-1a03-47f6-8b36-e84e47d335d8
https://vsee.com/clinic
Source: 57dba5dd-1a03-47f6-8b36-e84e47d335d8

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)