mlx vulnerabilities
CVEs whose affected-version data names the mlx package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-62609High· 7.5MLX is an array framework for machine learning on Apple silicon
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is deref…
▾ Twilightml-explore · mlxEPSS 0.38%via NVD
CVE-2025-62608Critical· 9.1MLX is an array framework for machine learning on Apple silicon
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds…
▾ Midnightml-explore · mlxEPSS 0.53%via NVD