SQLite Critical CVEs or LLM Slop?
Critical CVE issued for hallucinated SQLite vulnerability

A newly created GitHub repo published a batch of SQLite vulnerability advisories, quickly flagged as critical by NVD and CISA. JFrog's investigation revealed the cited code didn't exist, PoCs didn't trigger crashes, and none appear on SQLite's official advisory page. AI-detection tools flagged the advisories as AI-generated. The incident exposes systemic flaws in automated vulnerability ingestion, where fabricated CVEs can slip through and waste security teams' time.
Because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GHSA, downstream databases, and enterprise scanners.