Someone used an LLM to mass-produce fake vulnerability reports against SQLite — and the official CVE system waved them through. CVE-2026-51302 through 51304 landed 9.8 Critical scores; Red Hat briefly rated one a perfect 10.0. This isn’t a product, it’s a JFrog Research investigation, and Hacker News pushed it to 508 points because the target is the pipeline every security scanner trusts.
What JFrog actually found
JFrog verified every claim. The “vulnerable” function exprComputeOperands() doesn’t exist in SQLite. One advisory cited lines 3555–3575 in a 2,706-line file. Not a single PoC crashed anything, even under AddressSanitizer. The source GitHub account pushed 55 advisories in four days — 54 pure fabrication, all flagged as AI-generated by GPTZero. SQLite upstream confirmed the CVEs are fictitious.
Why the slop got through
MITRE’s CVE submission process has no identity verification, and NVD gutted manual review back in 2024. Nobody reproduces anything before publication. So hallucinated bugs flow straight into enterprise scanners, and security teams burn real hours patching vulnerabilities that never existed. One person with a chatbot just stress-tested the world’s vulnerability database — and it failed.
You Might Also Like
- Jamesob Local llm the 2026 Field Manual for Running Sota Models on Your own Hardware
- Llm Skirmish What Happens When you let ai Models Fight Each Other in an rts Game
- Sakana ai doc to Lora Text to Lora Your llm Just got a Permanent Memory Upgrade
- Saguaro Speculative Speculative Decoding the yo Dawg i Heard you Like Speculation Approach to Faster llm Inference
- Rfc 406i Rags Rejection of Artificially Generated Slop the Open Source Communitys Copy Paste Defense Against ai Spam prs

Leave a comment