{"id":"CVE-2025-62609","aliases":["GHSA-j842-xgm4-wf88","PYSEC-2025-139"],"url":"https://o3.security/vulnerability/CVE-2025-62609","summary":"MLX has Wild Pointer Dereference in load_gguf()","details":"MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched in version 0.29.4.","published":"2025-11-21T18:57:45.930Z","modified":"2026-07-15T01:49:20.539879748Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mlx","fixedVersion":"0.29.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62609.json"},{"type":"ADVISORY","url":"https://github.com/ml-explore/mlx/security/advisories/GHSA-j842-xgm4-wf88"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62609"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:20.539879748Z"}}