JFrog finds a batch of critical SQLite CVEs are LLM-hallucinated vulnerabilities
Critical CVE issued for hallucinated SQLite vulnerability
JFrog's security team audited six critical SQLite CVEs from a GitHub repo and found them all to be AI-fabricated. The cited functions don't exist in the referenced versions, PoCs don't crash, and SQLite's official advisory page lists none of them. CVE-2026-51302 was initially scored 10.0 by Red Hat, later downgraded to 7.6. Gptzero flagged the advisory text itself as AI-generated.
Why it matters: JFrog researchers confirmed a batch of SQLite 'critical CVEs' were AI hallucinations—PoCs didn't work, cited code didn't exist, and SQLite's official advisory page listed none of them. Red Hat quietly downgraded one from 10.0 to 7.6. A rare case of AI slop causing real confusi...