A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path r…
中危 CVSS 6.3
摘要
A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. Upgrading to version 3.6.2 is able to address this issue. It is recommended to apply a patch to fix this issue. The pull request to fix this issue requires some minor changes.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
Lint 边界警告 (1)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://pypi.org/project/pyod/3.6.2/
数据来源
- NVD DATABASE
原始链接
- https://github.com/yzhao062/pyod/
- https://github.com/yzhao062/pyod/issues/697
- https://github.com/yzhao062/pyod/pull/698
- https://pypi.org/project/pyod/3.6.2/
- https://vuldb.com/cve/CVE-2026-15529
- https://vuldb.com/submit/854559
- https://vuldb.com/vuln/377872
- https://vuldb.com/vuln/377872/cti
- https://github.com/yzhao062/pyod/issues/697
时间线
- nvd_ingest NVD