Tools AI-Found Vulnerability Register aifv-0001
Register entry
SQLite integer truncation found with Google Big Sleep, cut off before exploitation
- CVE
- CVE-2025-6965
- Project
- SQLite
- Component
- aggregate term handling
- Finder
- Google Big Sleep
- Autonomy
- agent assisting a named human researcher
- Evidence tier
- Credits array names the finder
- Assigner
- Severity
- 7.2 High (CVSS 4.0)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
An integer truncation in SQLite before 3.50.2 where the number of aggregate terms could exceed the columns available, published by Google as CNA on 15 July 2025. Google says the flaw was known only to threat actors and about to be used, and that Big Sleep with Threat Intelligence Group input identified it first.
Credit as recorded: Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep. The credit names a human researcher with assistance from the agent, so the flagship result is human-plus-agent while the routine Big Sleep records name the agent alone. Date basis: datePublic.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Google Cloud CISO Perspectives on Big Sleepcloud.google.com/blog/products/identity-security/cloud-ciso-…
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026