A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
{
"cwe_ids": [
"CWE-20",
"CWE-502"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15529.json",
"cna_assigner": "VulDB"
}{
"extracted_events": [
{
"introduced": "3.5.0"
},
{
"last_affected": "3.5.0"
},
{
"introduced": "3.5.1"
},
{
"last_affected": "3.5.1"
},
{
"introduced": "3.5.2"
},
{
"last_affected": "3.5.2"
},
{
"introduced": "3.5.4"
},
{
"last_affected": "3.5.4"
},
{
"introduced": "3.6.0"
},
{
"last_affected": "3.6.0"
},
{
"introduced": "3.6.1"
},
{
"last_affected": "3.6.1"
}
],
"source": "AFFECTED_FIELD"
}