Hacker News
JFrog: 54 of 55 SQLite CVE Advisories From One GitHub Account Were LLM-Fabricated — Including Six Rated Critical
JFrog Security Research documented six fabricated SQLite CVEs from a newly created repo (programmervuln/cveadvisory-), including CVE-2026-51302 and CVE-2026-51303 at CVSS 9.8 Critical and CVE-2026-51300 at 9.1. The advisories cite functions that don't exist in the targeted versions, reference line 3,575 in a json.c file that is only 2,706 lines long, describe patches absent from actual commits, and ship non-functional PoCs. JFrog concluded 54 of 55 examined reports from the source were fabricated — systemic pollution of the vulnerability databases that enterprise security automation trusts as ground truth.
↳ Follow the thread