AI‑generated fake SQLite CVEs uncovered, MITRE rejects 54 entries
Security researchers at JFrog examined a batch of vulnerability reports that claimed serious flaws in the SQLite database. All six SQLite advisories they tested were fabricated, and a review of the full set of 55 submissions found 54 completely false CVE entries. The bogus reports, likely generated by AI, had been entered into public databases such as the National Vulnerability Database and assigned high severity scores, with one even receiving a CVSS 10.0 rating from Red Hat.
MITRE subsequently rejected the 54 fake SQLite CVEs after the findings were reported. The episode highlights weaknesses in the CVE submission process, where verification is not mandatory and automated tools may ingest false data, leading to unnecessary investigations and patching efforts.
Entities: JFrog Security Research · Mitre · National Institute of Standards and Technology (NIST) · Red Hat · SQLite