Skip to content
pyodGHSA-997v-r4v7-9f3g

PyOD persistence.load deserializes untrusted artifacts before validation

Medium6.3CVE-2026-15529 · Published Jul 13, 2026 · updated Sep 10, 2026

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes.

GitHub advisory

Affected versions

PackageAffectedFixed in
pyod
PyPI
>= 3.5.0, < 3.6.23.6.2
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.