Skip to content
theregister·

🚨49 Fake CVEs in SQLite and Libraw Exposed as AI-Generated

AI-generated fake security alerts are now a real threat

TL;DR

Security researchers debunked 49 fake CVEs, likely generated by AI, targeting SQLite and libraw. JFrog found them all to be false positives, highlighting the need for verification.

JFrog recently exposed a batch of 49 fake CVEs published in a GitHub repository as AI-generated garbage. These advisories targeted SQLite and libraw but were quickly debunked by security researchers who found no reproducible vulnerabilities. This incident highlights the growing issue of automated vulnerability ingestion and the need for rigorous verification processes, especially with the rise of generative AI tools.

49 Fake CVEs in SQLite and Libraw Exposed as AI-Generated — theregister

Key Points

1

Security researchers found six supposed SQLite vulnerabilities to be completely false, likely generated by AI.

2

The US National Institute of Standards and Technology (NIST) had a backlog of over 27,000 unprocessed CVEs as of late 2025.

3

JFrog recommended verifying vendor corroboration and checking for suspicious metadata before acting on newly published CVEs.

4

GitHub has not yet removed the repo from their platform despite flagging by JFrog, Red Hat, and NVD.

5

The incident underscores a systemic issue with automated vulnerability ingestion and highlights the need for better verification practices.

Why It Matters

If you're managing security advisories or working on open-source projects like SQLite or libraw, this is crucial. The ease of generating fake CVEs means defenders must verify every alert meticulously to avoid false alarms or unnecessary panic.

AI-generatedCVESQLitelibrawJFrog

Frequently Asked Questions

Why does this matter?

If you're managing security advisories or working on open-source projects like SQLite or libraw, this is crucial. The ease of generating fake CVEs means defenders must verify every alert meticulously to avoid false alarms or unnecessary panic.

What happened?

Security researchers debunked 49 fake CVEs, likely generated by AI, targeting SQLite and libraw. JFrog found them all to be false positives, highlighting the need for verification.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,577 builders reading daily.

Also get