Medium severity6.3NVD Advisory· Published Jul 13, 2026· Updated Jul 20, 2026
CVE-2026-15529
CVE-2026-15529
Description
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyodPyPI | >= 3.5.0, < 3.6.2 | 3.6.2 |
Affected products
1Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-997v-r4v7-9f3gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-15529ghsaADVISORY
- github.com/yzhao062/pyod/commit/16e6e3ad8921a4e18ccc8c2afe474db7d002c001ghsaWEB
- github.com/yzhao062/pyod/issues/697nvdWEB
- github.com/yzhao062/pyod/pull/698nvdWEB
- github.com/yzhao062/pyod/releases/tag/v3.6.2ghsaWEB
- pypi.org/project/pyod/3.6.2ghsaWEB
- vuldb.com/cve/CVE-2026-15529nvdWEB
- vuldb.com/submit/854559nvdWEB
- vuldb.com/vuln/377872nvdWEB
- vuldb.com/vuln/377872/ctinvdWEB
- pypi.org/project/pyod/3.6.2/nvd
News mentions
0No linked articles in our index yet.