CVE-2026-15529

A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
Configurations

No configuration.

History

20 Jul 2026, 07:16

Type Values Removed Values Added
References
  • () https://pypi.org/project/pyod/3.6.2/ -
Summary (en) A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. (en) A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.

14 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/yzhao062/pyod/issues/697 - () https://github.com/yzhao062/pyod/issues/697 -

13 Jul 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 04:16

Updated : 2026-07-20 07:16


NVD link : CVE-2026-15529

Mitre link : CVE-2026-15529

CVE.ORG link : CVE-2026-15529


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data