SQLite Critical CVEs or LLM Slop? | JFrog
- Over the past few days, a newly created GitHub repo (programmervuln/cveadvisory-) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one).
- NVD quickly flagged these as critical, and CISA's ADP agreed.
- But when JFrog security researchers dug in to verify, the claims fell apart: The cited code didn't even exist in those versions or referenced unrelated logic.
Unverified
- Over the past few days, a newly created GitHub repo (programmervuln/cveadvisory-) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one).
- NVD quickly flagged these as critical, and CISA's ADP agreed.
- But when JFrog security researchers dug in to verify, the claims fell apart: The cited code didn't even exist in those versions or referenced unrelated logic.
Sources: Jfrog