{"id":"CVE-2026-15529","aliases":["GHSA-997v-r4v7-9f3g"],"url":"https://o3.security/vulnerability/CVE-2026-15529","summary":"yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization","details":"A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.","published":"2026-07-13T03:45:08.697Z","modified":"2026-09-03T19:40:40.376728033Z","cvss":null,"epss":{"score":0.00441,"percentile":0.36878,"asOf":"2026-09-03"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyod","fixedVersion":"3.6.2"}],"fix":{"url":"https://github.com/yzhao062/pyod/pull/698","label":"yzhao062/pyod#698"},"references":[{"type":"WEB","url":"https://github.com/yzhao062/pyod/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15529.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15529"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-15529"},{"type":"ADVISORY","url":"https://vuldb.com/submit/854559"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/377872"},{"type":"REPORT","url":"https://github.com/yzhao062/pyod/issues/697"},{"type":"REPORT","url":"https://vuldb.com/vuln/377872/cti"},{"type":"FIX","url":"https://github.com/yzhao062/pyod/pull/698"},{"type":"FIX","url":"https://pypi.org/project/pyod/3.6.2/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T19:40:40.376728033Z"}}