Vulnerability Description
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/yzhao062/pyod/
- https://github.com/yzhao062/pyod/issues/697
- https://github.com/yzhao062/pyod/pull/698
- https://pypi.org/project/pyod/3.6.2/
- https://vuldb.com/cve/CVE-2026-15529
- https://vuldb.com/submit/854559
- https://vuldb.com/vuln/377872
- https://vuldb.com/vuln/377872/cti
- https://github.com/yzhao062/pyod/issues/697
FAQ
What is CVE-2026-15529?
CVE-2026-15529 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path re...
How severe is CVE-2026-15529?
CVE-2026-15529 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15529?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.