VDB
Sign up
CRITICAL9.1

PYSEC-2025-138

Quick fix

PYSEC-2025-138 — mlx: upgrade to the fixed version with the command below.

pip install --upgrade 'mlx>=0.29.4'

Details

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue has been patched in version 0.29.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mlx
Introduced in: 0Fixed in: 0.29.4
Fixpip install --upgrade 'mlx>=0.29.4'

References