NumPy releases before 1.16.3 changed the safety boundary around loading arrays that contain Python objects. Public advisory sources describe the risk as unsafe pickle deserialization through numpy.load(), while also noting that the dangerous condition depends on loading pickled data from an untrusted source [S1][S2]. NumPy's own documentation records that allow_pickle defaults to False in 1.16.3 because loading pickled data can execute arbitrary code [S3].
Impact
Applications that load externally supplied .npy or .npz data with affected NumPy releases and pickle loading enabled may cross a code-execution trust boundary [S1][S2]. The repository evidence by itself does not prove a deployed exploit path; impact depends on whether untrusted files can reach the affected load call.
Covered by FixVibe
FixVibe's GitHub repo scans flag repositories that combine an affected NumPy version with Python source that calls numpy.load(..., allow_pickle=True), showing the dependency file, source file and line, and fixed version.
Remediation
Upgrade NumPy to 1.16.3 or newer and rebuild every runtime, worker, notebook, CI job, virtualenv, or container image that can load NumPy arrays [S3][S4]. Remove allow_pickle=True or set allow_pickle=False anywhere loaded data can cross a user, tenant, upload, email, object-storage, or external-service trust boundary. If object arrays are unavoidable, restrict loading to trusted internal artifacts with provenance checks and prefer non-pickle formats for exchanged data.
