YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0001

Register entry

SQLite integer truncation found with Google Big Sleep, cut off before exploitation

CVE
CVE-2025-6965
Project
SQLite
Component
aggregate term handling
Finder
Google Big Sleep
Autonomy
agent assisting a named human researcher
Evidence tier
Credits array names the finder
Assigner
Google
Severity
7.2 High (CVSS 4.0)
Bounty
None published
Confidence
CONFIRMED

What happened

An integer truncation in SQLite before 3.50.2 where the number of aggregate terms could exceed the columns available, published by Google as CNA on 15 July 2025. Google says the flaw was known only to threat actors and about to be used, and that Big Sleep with Threat Intelligence Group input identified it first.

Credit as recorded: Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep. The credit names a human researcher with assistance from the agent, so the flagship result is human-plus-agent while the routine Big Sleep records name the agent alone. Date basis: datePublic.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026