STUPID-2026-0049
AI 'CVE slop' is drowning open-source maintainers: 60-80% of HackerOne submissions now invalid
Instruction given
Generate and submit security vulnerability reports to open-source projects.
Expected behavior
Only submit real, reproducible vulnerabilities; do not fabricate functions, commits, or patches.
Actual behavior
Maintainers across the ecosystem are inundated with AI-written reports citing nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced. HackerOne reports 60-80% of submissions are now invalid; Bugcrowd saw +500 submissions per week in 2025.
Damage
Volunteer maintainers — including the Python Software Foundation's Seth Larson, who triages CPython, pip, urllib3, and Requests — face a sustained flood of hallucinated reports that take a serious mental toll and waste scarce time debunking non-bugs.
Classification
- Agent
- Multiple LLMs
- Failure mode
- Hallucination
- Root cause
- Confidence Miscalibration
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.