SQLite Hit by Fake Critical CVEs Generated by LLM Slop
jedisct1 · x · 2026-08-03
JFrog Security Research recently uncovered that a newly created GitHub repo submitted a batch of critical vulnerability advisories for SQLite, which were quickly flagged as 'Critical' by NVD and CISA. However, deep auditing revealed these reports are likely LLM slop:
- Fake Code References: The advisory mentions functions and code lines that do not exist in the specified versions or refer to unrelated logic.
- Ineffective PoCs: Testing the provided proof-of-concept payloads failed to trigger any crashes.
- Unlisted by Official Channels: None of these CVEs are present on SQLite's official security advisories.
- AI Signatures: The advisories trigger AI-generated content warnings on GPTZero and exhibit typical LLM phrasing.
One CVE initially scored 10.0 by Red Hat has now been downgraded to 7.6 High. This incident highlights the vulnerability of current CVE submission pipelines to AI-generated misinformation.
More from Safety
- OpenAI Disrupts Cambodia-Based Criminal Scam Operation Using ChatGPT — OpenAI News · 2026-08-04
- Use Vendor Contracts to Mandate AI-Assisted Code Security Audits — chrisrohlf · 2026-08-03
- INTERPOL: AI Drives Over Half of Cybercrime in Africa — RSync25 · 2026-08-03
- Critical CVE Issued for Hallucinated SQLite Vulnerability — ymir_e · 2026-08-03
- Nightcrawler: A Local AI Pentesting Agent Running Entirely on Smartphones — NickySlicks · 2026-08-03
- Grok Imagine Called Out for Leaking Users' AI Image Prompts — mark_k · 2026-08-03