JFrog exposes AI-generated fake SQLite CVEs
JFrog Security Research discovered that 54 out of 55 recent SQLite vulnerability advisories submitted to GitHub were entirely hallucinated by LLMs. The fake reports referenced non-existent C functions and received critical CVSS scores up to 10.0 before rejection, exposing flaws in automated vulnerability registries.
Automated CVE scoring and the rise of LLM slop threaten to overwhelm maintainers and undermine trust in security databases. Vulnerability databases blindly trusted plausible-sounding AI prose without verifying code existence or running proof-of-concept payloads. Maintainers are forced to waste valuable time and resources auditing phantom security flaws instead of patching actual code defects. CVE Numbering Authorities (CNAs) urgently need automated sandboxed PoC validation and strict reporter reputation systems to filter out AI-generated vulnerability spam.
DISCOVERED
1h ago
2026-08-03
PUBLISHED
2h ago
2026-08-03
RELEVANCE
AUTHOR
ymir_e

