PatchSiren

VSee CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH VSee CVE published 2026-07-20

CVE-2026-13381

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T21:16:46.660Z and has not been modified since then. CVE-2026-13381 is an Insecure Direct Object Reference (IDOR) vulnerability in VSee Clinic 7.1.26 and API 1.3.0. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other u [truncated]

CRITICAL VSee CVE published 2026-07-20

CVE-2026-13380

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 have a critical vulnerability (CVE-2026-13380) that exposes cleartext SFTP credentials in HTTP responses of unauthenticated endpoints when SFTP connections are configured. Organizations using these versions should immediately secure their SFTP connections and verify if they are affected. The CVE record was published on 2026-07-20T21:16:46.510Z. This vulnerabili [truncated]