CVE-2026-15529
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persi
CVSS
6.3
Medio
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Publicado: 13 jul 2026 · Última mod.: 20 jul 2026 · CWE-20 · CWE-502
0.3%EPSS · 30 días0.3%
2026-07-132026-07-20
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
- github.comhttps://github.com/yzhao062/pyod/
- github.comhttps://github.com/yzhao062/pyod/issues/697
- github.comhttps://github.com/yzhao062/pyod/pull/698
- pypi.orghttps://pypi.org/project/pyod/3.6.2/
- vuldb.comhttps://vuldb.com/cve/CVE-2026-15529
- vuldb.comhttps://vuldb.com/submit/854559
- vuldb.comhttps://vuldb.com/vuln/377872
- vuldb.comhttps://vuldb.com/vuln/377872/cti
- github.comhttps://github.com/yzhao062/pyod/issues/697
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2021-422379.8 CRÍ99.9%
KEV—80Sitecore XP Remote Command Execution Vulnerability12dCVE-2026-341978.8 ALT99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability6dCVE-2026-456598.8 ALT86.8%
KEV—76Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability19dCVE-2026-586449.8 CRÍ70.8%
KEV—71Microsoft SharePoint Deserialization of Untrusted Data Vulnerability4dCVE-2026-125699.8 CRÍ66.0%
KEV—70PTC Windchill and FlexPLM Improper Input Validation Vulnerability21dCVE-2026-505229.8 CRÍ97.2%
——29Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.6d