{"id":"CVE-2026-15529","title":"A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2","summary":"A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-20","CWE-502"],"published":"2026-07-13","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15529","references":[{"url":"https://github.com/yzhao062/pyod/","label":"cna@vuldb.com"},{"url":"https://github.com/yzhao062/pyod/issues/697","label":"cna@vuldb.com"},{"url":"https://github.com/yzhao062/pyod/pull/698","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-15529","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/854559","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/377872","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/377872/cti","label":"cna@vuldb.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15529"},{"url":"https://github.com/yzhao062/pyod/commit/16e6e3ad8921a4e18ccc8c2afe474db7d002c001"},{"url":"https://github.com/yzhao062/pyod"},{"url":"https://github.com/yzhao062/pyod/releases/tag/v3.6.2"},{"url":"https://pypi.org/project/pyod/3.6.2"},{"url":"https://pypi.org/project/pyod"},{"url":"https://github.com/advisories/GHSA-997v-r4v7-9f3g"}],"tags":["nvd","osv","pip"],"ingestedAt":"2026-07-13T04:24:09.669Z","epss":0.00441,"epssPercentile":0.37623,"aliases":["GHSA-997v-r4v7-9f3g","PYSEC-2026-3909"],"ecosystem":"pip","vendor":"pyod","product":"pyod","affected":["pyod >= 3.5.0, < 3.6.2"],"patched":["pyod 3.6.2"],"slug":"CVE-2026-15529","body":"## Overview\n\nA vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-15529)\n\nAffected packages:\n\n- `pyod >= 3.5.0, < 3.6.2`\n\nPatched in:\n\n- `pyod 3.6.2`\n\nSource: https://osv.dev/vulnerability/GHSA-997v-r4v7-9f3g","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}