CVE-2026-32711 is a high-severity Path Traversal vulnerability (CWE-22) affecting pydicom versions 2.0.0-rc.1 through 3.0.1, a Python package for DICOM files. An attacker can exploit this by crafting a malicious DICOMDIR ReferencedFileID, leading to arbitrary file read, copy, and potentially move or delete operations outside the intended File-set root. Rated with a CVSS score of 7.8 (HIGH), exploitation requires local access and user interaction, but results in high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability. The issue has been addressed in pydicom version 3.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 3.0.2CPE matchmatch criteria | cpe:2.3:a:pydicom:pydicom:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
Mar 20, 2026pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
Mar 20, 2026