{"id":"CVE-2026-13381","title":"VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint","summary":"VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and dele…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-639"],"vendor":"vsee","product":"clinic","affected":["clinic = 7.1.26","clinic_api = 1.3.0"],"published":"2026-07-20","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13381","references":[{"url":"https://labs.sra.io/posts/vseeclinic","label":"57dba5dd-1a03-47f6-8b36-e84e47d335d8"},{"url":"https://vsee.com/clinic","label":"57dba5dd-1a03-47f6-8b36-e84e47d335d8"}],"tags":["nvd"],"epss":0.00209,"epssPercentile":0.11303,"ingestedAt":"2026-08-15T15:26:57.693Z","slug":"CVE-2026-13381","body":"## Overview\n\nVSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.\n\n## Affected\n\n- `clinic = 7.1.26`\n- `clinic_api = 1.3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}