Vulnerabilities
Vulnerable Software
Ml-Explore:  >> Mlx  >> 0.0.11  Security Vulnerabilities
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue has been patched in version 0.29.4.
CVSS Score
9.1
EPSS Score
0.0
Published
2025-11-21
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched in version 0.29.4.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-11-21


Contact Us

Shodan ® - All rights reserved