Fetching from the wire…
Public story · 2026-08-04 · high
None of the 54 fabricated flaws appeared on SQLite's own advisory page, and MITRE's process didn't verify who filed them.
Why now: JFrog's fabricated-CVE analysis is the day's news itself, published August 4 with the 54-of-55 count as the first tally of that account's advisories.
JFrog found that 54 of 55 SQLite CVE advisories from one GitHub account were fabricated, the security firm said. Fed into an autonomous remediation agent, one of these fakes won't get caught. The agent will locate the named function, write a patch, and commit a real code change to fix a bug that was never there.
The cited code didn't exist in the named SQLite versions. The proof-of-concept payloads didn't trigger the crashes they claimed to cause, and none of the 54 showed up on SQLite's own advisory page.
MITRE's CVE submission process doesn't verify who's filing, per JFrog. Anyone can register a GitHub account and publish an advisory citing specific functions and line numbers that were never in the codebase. It lands in the same public database as confirmed vulnerabilities, with no gate that checks the claim against the vendor's own record first.
A human triager might notice the PoC doesn't crash anything. An agent built to patch first and verify later just ships the fix.
JFrog's finding covers one account and 55 advisories. There's no count yet for how many other fabricated entries sit in the same database, waiting for an agent to act on them.
Each link below shares sources, entities, or timing with this story.
JFrog criticizes SQLite / Shared entities / Same source / Shared topic / Earlier coverage
Linked by a graph relationship (JFrog criticizes SQLite); both cover CVE, GitHub, JFrog, SQLite CVE; cite the same source (JFrog).
OpenClaw uses SQLite / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenClaw uses SQLite); both cover GitHub, SQLite; overlapping topics (agent, code).
JFrog released Artifactory / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (JFrog released Artifactory); both cover CVE, JFrog; overlapping topics (account, agent).
OpenClaw uses SQLite / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenClaw uses SQLite); both cover GitHub, SQLite; overlapping topics (agent, code).
mempalace uses SQLite / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (mempalace uses SQLite); both cover GitHub, SQLite; earlier GitHub coverage from 2026-06-05.
JFrog criticizes SQLite / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (JFrog criticizes SQLite); both cover GitHub, SQLite; overlapping topics (agent, code, sqlite).
JFrog criticizes Langflow / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (JFrog criticizes Langflow); both cover CVE, PoC; overlapping topics (advisory, agent).
OpenClaw uses SQLite / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenClaw uses SQLite); both cover CVE, GitHub; overlapping topics (agent, code).