Checked August 17, 2026 via the GitHub Advisory Database API: all six fake SQLite CVEs rejected by MITRE still show CVSS up to 9.8 as type unreviewed, withdrawn_at null.
Eight ComfyUI experiments on a 4-character Anima (Qwen-DiT) LoRA in plain terms: the conditioning right before the DiT decides who appears, and outfit mix-ups come from a biased DiT LoRA.
Built a fictional idol label site with pi.dev + Qwen 3.7/3.8 and Astro. Generated characters, logos, and event photos via genserver — then shipped wireframes with SVG placeholders. Full failure log inside.
Tested on ComfyUI: Qwen3-4B–14B prompt writing, a 4B encoder bridge, and split conditioning all lost to one hand-written 507-token band prompt. An 896-caption audit shows the real fix.
Tested on an M4 Mac mini with one 4-girl Anima LoRA: expressions, poses, desk contact, and a high-five across 3 seeds. Sentence order and center slots decided who touched whom.
Tested on M4 Mac mini ComfyUI: with identical Qwen3-0.6B/T5 conditioning, the black tights land on the wrong girl only when the 4-char LoRA's DiT half is applied.
Gemini said 'I am a disgrace' 86 times in 2025. Traced the primary sources: no fix announcement found, only CLI-side loop-stopping guards, and Gemini 3.1 Pro was still looping in 2026.
Tested on M4 Mac mini ComfyUI: 8 on/off combos of three actions × 3 seeds on a 4-character Anima LoRA. Roles read at 3/3, but hands and skirts landed on the wrong girl.
Tested on M1 Max 64GB: a 50M resampler predicts Anima's 4-char conditioning from short triggers. Train fits at cos distance 0.005, held-out order breaks; template P3 goes 15/16.
Tested on Anima-Base v1.0: no prompt hit the 512-token cap, cosine similarity moved the wrong way, and only the DiT-side conditioning changed who got drawn.
WordPress 7.0.3 (Aug 6, 2026) closes CVE-2026-64638 / XSS2Shell (CVSS 8.9): a whitespace tag like `< area` slips past strip_tags but KSES restores it, giving pre-auth login XSS that chains to PHP RCE. All versions affected; fix backported to 4.7.