Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 20, 2026
yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization
CVE-2026-15529
Description
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/yzhao062/pyod/pull/698mitreissue-trackingpatch
- pypi.org/project/pyod/3.6.2/mitrepatch
- vuldb.com/cve/CVE-2026-15529mitrethird-party-advisory
- vuldb.com/submit/854559mitrethird-party-advisory
- github.com/yzhao062/pyod/issues/697mitreissue-tracking
- vuldb.com/vuln/377872mitrevdb-entrytechnical-description
- vuldb.com/vuln/377872/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.