CVE-2026-15529 | yzhao062 pyod up to 3.6.1 persistence.py pyod.utils.persistence.load path deserialization (Issue 697 / EUVD-2026-43275)
A vulnerability marked as critical has been reported in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization.
This vulnerability is identified as CVE-2026-15529. The attack can be initiated remotely. There is not any exploit available.
It is recommended to apply a patch to fix this issue.
The pull request to fix this issue requires some minor changes.