VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://labs.sra.io/posts/vseeclinic |
|
| https://vsee.com/clinic |
|
History
Tue, 21 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server. | |
| Title | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses | |
| Weaknesses | CWE-201 CWE-312 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SRA
Published:
Updated: 2026-07-21T17:16:05.916Z
Reserved: 2026-06-25T21:22:28.646Z
Link: CVE-2026-13380
Updated: 2026-07-21T16:38:08.881Z
No data.
No data.
OpenCVE Enrichment
No data.