AI slop pollutes the CVE pipeline with fake vulns
With NIST still buried under its backlog, expect AI-generated bogus reports to continue
AI-generated fake vulnerabilities have infiltrated the CVE pipeline, posing a threat to software supply chains. Six SQLite vulnerabilities, initially listed with high CVSS scores, turned out to be bogus upon testing. JFrog, a software supply chain security company, discovered these vulnerabilities after running them through an AI checker.
The CVSS scores ranged from 9.8 to 7.5, but none of the six advisories described a reproducible vulnerability. Another 54 fake CVEs were found in a GitHub repository, claiming security vulnerabilities in open-source libraries like RAW image processing library libraw and Arduino audio decoding library ESP32-audioI2S. Experts warn that the lack of mandatory checkpoints in the current system allows fake advisories to slip through undetected.
Defenders are advised to verify the legitimacy of new CVEs by checking vendor confirmation, references to commits or pull requests, and suspicious metadata before acting on them.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- AI slop pollutes the CVE pipeline with fake vulns theregister.com