tink / link log #systemcrafters

< antti > dropped a link

SQLite Critical CVEs or LLM Slop? - JFrog Security Research

https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/

Afek Berger, JFrog Security Researcher | 30 Jul, 2026

what others said

Commenters agreed the issue reduces signal-to-noise ratio for organizations mandated to patch CVEs, though one noted LLMs still discover legitimate flaws. The strongest objection highlighted that critical ratings were assigned to non-existent vulnerabilities, such as misidentifying a code comment as vulnerable, which increased triage costs and delayed real reports. Specific concerns included the systemic risk of flooding submission systems with false reports, the mixing of unrelated product CVEs in single repositories, and the irony of using AI detection tools on an article flagged as AI-generated itself.