A AegiFlow
MEDIUMCVSS 5.3EPSS 0.4%

CVE-2026-15529

PyOD persistence.load deserializes untrusted artifacts before validation

Published
2026-07-13
Modified
2026-09-03
EPSS percentile
37%
Aliases
GHSA-997v-r4v7-9f3g
Sources
github-advisory

Summary

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIpyod3.6.2

Remediation: Upgrade to 3.6.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.