Fetching from the wire…
Public story · 2026-08-04 · high
None of the 54 fabricated flaws appeared on SQLite's own advisory page, and MITRE's process didn't verify who filed them.
Why now: JFrog's fabricated-CVE analysis is the day's news itself, published August 4 with the 54-of-55 count as the first tally of that account's advisories.
JFrog found that 54 of 55 SQLite CVE advisories from one GitHub account were fabricated, the security firm said. Fed into an autonomous remediation agent, one of these fakes won't get caught. The agent will locate the named function, write a patch, and commit a real code change to fix a bug that was never there.
The cited code didn't exist in the named SQLite versions. The proof-of-concept payloads didn't trigger the crashes they claimed to cause, and none of the 54 showed up on SQLite's own advisory page.
MITRE's CVE submission process doesn't verify who's filing, per JFrog. Anyone can register a GitHub account and publish an advisory citing specific functions and line numbers that were never in the codebase. It lands in the same public database as confirmed vulnerabilities, with no gate that checks the claim against the vendor's own record first.
A human triager might notice the PoC doesn't crash anything. An agent built to patch first and verify later just ships the fix.
JFrog's finding covers one account and 55 advisories. There's no count yet for how many other fabricated entries sit in the same database, waiting for an agent to act on them.
Each link below shares sources, entities, or timing with this story.
JFrog Security Research documented six invented SQLite CVEs from a newly created repo (programmervuln/cveadvisory-), including CVE-2026-51302 and CVE-2026-51303 at CVSS 9.8 and CVE-2026-51300 at 9.1. The advisories cite functions that don't exist in the targeted versions, refe...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
The submission titled "CEO fired developers to make room for AI. Developers create open source AI CEO" pointed at SenteLabsAI/OpenExecutive, an Apache-2.0 FastAPI and Next.js 15 app running eight specialist Claude agents (CSO, CFO, CHRO, General Counsel, COO, CMO, CPO, Board C...
Triple-stream retrieval (BM25 keyword, vector embeddings, knowledge-graph traversal) fused via Reciprocal Rank Fusion on the iii engine, with SQLite for state and an in-memory vector index, no external database. The economic claim: ~170K tokens/year (~$10) versus ~650K tokens...
claude-mem hit 80,189 stars at v12.6.4, with 1,840 commits and 109 contributors. It hooks five agent lifecycle events to capture observations, compresses them through Claude's agent SDK into SQLite, and reinjects relevant context on new sessions. No manual tagging. One npx com...
MemPalace (~53.6K stars) claims best-benchmarked, against mem0 (~57.8K) and claude-mem (~80.8K) (GitHub). Agent memory went from experimental nicety to a competitive subcategory with published benchmarks. Pair this with the local-first angle: Mnemo offers a Rust + SQLite + pet...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.