Fetching from the wire…
Public story · 2026-08-03 · high
Two of the six Critical fakes claimed a CVSS score of 9.8, high enough to auto-block a build in most scanners.
Why now: JFrog's research is dated August 3, and CVSS-gated build blocks are still the default trust setting in most enterprise CI pipelines.
JFrog found 54 of 55 SQLite CVE advisories from one GitHub account were fabricated by an LLM, per its research into the repo programmervuln/cveadvisory-.
Six of those 54 were rated Critical, the severity tier that triggers automatic build blocks in most enterprise dependency scanners. CVE databases are the ground truth those scanners trust, and this account polluted it without writing a single real exploit.
Two of the six Critical advisories, CVE-2026-51302 and CVE-2026-51303, carry a CVSS score of 9.8. A third, CVE-2026-51300, scored 9.1.
None of it holds up under a close read, per JFrog. The advisories cite functions absent from the SQLite versions they target.
One points to line 3,575 of a json.c file that only runs 2,706 lines. The patches described as fixes don't appear in SQLite's real commit history, and the attached proof-of-concept exploits don't run.
Nothing here required a real vulnerability. An account with an API key and a few spare hours produced advisories convincing enough to pass, per JFrog. That's all a CVSS-gated scanner checks before it fails a build.
Each link below shares sources, entities, or timing with this story.
LLM uses OpenAI / Shared entities / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover CVE, JFrog; earlier CVE coverage from 2026-07-31.
Simon Willison released LLM / Shared entity: GitHub / Shared topic / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover GitHub; overlapping topics (account, automation).
LLM uses OpenAI / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; earlier LLM coverage from 2026-07-27.
LLM uses OpenAI / Shared entity: CVE / Earlier coverage / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover CVE; earlier CVE coverage from 2026-07-23.
LLM uses OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover CVE, CVSS; overlapping topics (advisory, cvss).
Linked by a graph relationship (LLM uses OpenAI); both cover CVSS, GitHub; overlapping topics (account, advisory).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.