| |
JFrog security researchers discovered that a batch of SQLite vulnerability advisories published on GitHub and quickly flagged as critical by NVD and CISA appear to be AI-generated fabrications ("LLM slop"), with cited code that doesn't exist in the affected versions, non-functional proof-of-concept payloads, and no listings on SQLite's official advisory page. The researchers verified the claims through source code inspection, isolated testing, and PoC execution, confirming the vulnerabilities are false, leading to at least one CVE being downgraded from critical (10.0) to high (7.6) severity after review.
Read Full Article →
← More Tech news