SQLite Hit by Fake Critical CVEs Generated by LLM Slop

jedisct1 · x · 2026-08-03

JFrog Security Research recently uncovered that a newly created GitHub repo submitted a batch of critical vulnerability advisories for SQLite, which were quickly flagged as 'Critical' by NVD and CISA. However, deep auditing revealed these reports are likely LLM slop:

One CVE initially scored 10.0 by Red Hat has now been downgraded to 7.6 High. This incident highlights the vulnerability of current CVE submission pipelines to AI-generated misinformation.

Original post →

More from Safety

Safety channel →