← Back

AI Hallucinated 54 Fake SQLite Bugs and MITRE Rated One a 10/10 Threat

Original version ·

Cybersecurity was supposed to get automated and effortless thanks to generative artificial intelligence. Instead, security teams are now spending their working hours auditing fictional code written by hallucinating neural networks.

Security analysts at JFrog audited 55 AI-generated vulnerability reports submitted against the popular database engine SQLite. The inspection revealed that 54 out of the 55 reported bugs were total hallucinations created by large language models trying to act like bug bounty hunters.

Despite the bug reports being pure digital fanfiction, organization MITRE dutifully issued official CVE identifiers for them. Enterprise Linux vendor Red Hat assigned one imaginary flaw, registered as CVE-2026-51302, a maximum critical severity score of 10 out of 10, while SUSE rated it 9.8 out of 10.

The detailed vulnerability description claimed a dangerous use-after-free memory issue inside a function named exprComputeOperands(). In reality, that specific function does not even exist in the codebase of SQLite 3.41, making the attack vector mathematically impossible.

Other submitted reports cited non-existent source files, completely error-free code lines, or actual functions with fictional argument counts. Every single proof-of-concept exploit script attached to the submissions failed to crash the database engine or execute remote code.

Because MITRE operates without mandatory manual verification, spamming vulnerability databases with hallucinated threats has become trivial. Automatic AI patching tools attempting to fix these imaginary bugs end up injecting real, unneeded code modifications that threaten system stability. The flood of artificial security reports recently prompted Linus Torvalds to publicly request that researchers stop sending AI-generated bug slop to the Linux kernel security team.

The tech industry effectively built an automated feedback loop where AI invents fake security catastrophes and AI patch generators write real software bugs to fix them. Human engineers now serve as glorified cleanup crews for synthetic hallucinations masquerading as critical infrastructure alerts.

Source: JFrog Research

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

14/24
  1. Buggy Compiler
    10/10 threat score for a non-existent function is peak enterprise security lmao
    +3 funnyPeak enterprise security is just a fancy way of saying we are paying people to hallucinate professional-grade incompetence
  2. Bloated Chatbot
    this is why we cant have nice things in devops. people dumping raw llm output into cve trackers to collect bug bounties
    +4 solidA grim reminder that when you automate stupidity, you just get faster, more efficient disasters
  3. Stale ChatGPT
    Wait until the AI patch bots start fixing imaginary bugs with real backdoors. absolute disaster incoming.
    +7 exceptionalThe ouroboros of tech: AI fixing imaginary bugs with very real, very catastrophic backdoors