pyodGHSA-997v-r4v7-9f3g
PyOD persistence.load deserializes untrusted artifacts before validation
Medium6.3CVE-2026-15529 · Published Jul 13, 2026 · updated Sep 10, 2026
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pyod PyPI | >= 3.5.0, < 3.6.2 | 3.6.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20, CWE-502
- Also known as
- CVE-2026-15529, PYSEC-2026-3909
- nvd.nist.gov/vuln/detail/CVE-2026-15529
- github.com/yzhao062/pyod/issues/697
- github.com/yzhao062/pyod/pull/698
- github.com/yzhao062/pyod/commit/16e6e3ad8921a4e18ccc8c2afe474db7d002c001
- github.com/yzhao062/pyod
- github.com/yzhao062/pyod/releases/tag/v3.6.2
- pypi.org/project/pyod/3.6.2
- vuldb.com/cve/CVE-2026-15529
- vuldb.com/submit/854559
- vuldb.com/vuln/377872
- vuldb.com/vuln/377872/cti