MEDIUM6.3
GHSA-997v-r4v7-9f3g
PyOD persistence.load deserializes untrusted artifacts before validation
Quick fix
GHSA-997v-r4v7-9f3g — pyod: upgrade to the fixed version with the command below.
pip install --upgrade 'pyod>=3.6.2'Details
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-15529[ADVISORY]
- https://github.com/yzhao062/pyod/issues/697[WEB]
- https://github.com/yzhao062/pyod/pull/698[WEB]
- https://github.com/yzhao062/pyod/commit/16e6e3ad8921a4e18ccc8c2afe474db7d002c001[WEB]
- https://github.com/yzhao062/pyod[PACKAGE]
- https://github.com/yzhao062/pyod/releases/tag/v3.6.2[WEB]
- https://pypi.org/project/pyod/3.6.2[WEB]
- https://vuldb.com/cve/CVE-2026-15529[WEB]
- https://vuldb.com/submit/854559[WEB]
- https://vuldb.com/vuln/377872[WEB]
- https://vuldb.com/vuln/377872/cti[WEB]