Top AI Product

Every day, hundreds of new AI tools launch across Product Hunt, Hacker News, and GitHub. We dig through the noise so you don't have to — surfacing only the ones worth your attention with honest, no-fluff reviews. Explore our latest picks, deep dives, and curated collections to find your next favorite AI tool.


幻觉 SQLite CVE 事件:LLM slop 攻陷 CVE 体系(JFrog 调查)— fake AI-written bugs scored 9.8 Critical

Someone used an LLM to mass-produce fake vulnerability reports against SQLite — and the official CVE system waved them through. CVE-2026-51302 through 51304 landed 9.8 Critical scores; Red Hat briefly rated one a perfect 10.0. This isn’t a product, it’s a JFrog Research investigation, and Hacker News pushed it to 508 points because the target is the pipeline every security scanner trusts.

What JFrog actually found

JFrog verified every claim. The “vulnerable” function exprComputeOperands() doesn’t exist in SQLite. One advisory cited lines 3555–3575 in a 2,706-line file. Not a single PoC crashed anything, even under AddressSanitizer. The source GitHub account pushed 55 advisories in four days — 54 pure fabrication, all flagged as AI-generated by GPTZero. SQLite upstream confirmed the CVEs are fictitious.

Why the slop got through

MITRE’s CVE submission process has no identity verification, and NVD gutted manual review back in 2024. Nobody reproduces anything before publication. So hallucinated bugs flow straight into enterprise scanners, and security teams burn real hours patching vulnerabilities that never existed. One person with a chatbot just stress-tested the world’s vulnerability database — and it failed.


You Might Also Like


Discover more from Top AI Product

Subscribe to get the latest posts sent to your email.



Leave a comment