JFrog: 54 of 55 SQLite CVE advisories from one account were fabricated, and autonomous patching agents are the downstream victim
Published 2026-07-30 and widely discussed this week, JFrog analyzed 55 advisories from the GitHub account programmervuln/cveadvisory- and found 54 completely fabricated, with one real bug. The cited code did not exist in the named versions or referenced unrelated logic, proof-of-concept payloads failed to trigger crashes, and none appeared on SQLite's official advisory page. The agent-specific consequence is the part worth acting on: an autonomous remediation agent fed these CVEs will attempt to locate the vulnerable function, generate a patch, or recommend changes against code that does not exist, introducing real modifications to fix an imaginary bug. Root cause is MITRE's CVE submission process lacking identity verification combined with NIST's analysis pipeline collapse in February 2024. Note this is five days old rather than inside the 48-hour window.
↳ Follow the thread