Skip to content

anthropic

Claude flagged 29,000 possible bugs. Upstream fixed 516

Claude News

Outside security firms reviewed 6,123 Claude findings and confirmed 5,674 of them as real bugs. As of October 2, only 516 had been patched upstream, according to a disclosure dashboard cited by The New Stack.

Anthropic's answer is in a launch post from Anthropic: stop making maintainers wait for human reviewers, and send the model's raw reports straight to the projects that want them.

At a glance

  • Anthropic has launched OSS Scanner, a free, opt-in service that periodically scans eligible open-source projects with its strongest models, including Claude Mythos, and sends findings without human review or triage.
  • In six months its models surfaced more than 29,000 candidate vulnerabilities, but Anthropic's human pipeline has triaged only about 6,000, leaving roughly 23,000 unreviewed, per The New Stack.
  • In an early test, 85 of 97 critical and high findings passed expert review, but maintainers say severity is sometimes inflated, and every fix still has to be tested and shipped by them.

If you have not been following, here is the backstory. According to the Cloud Security Alliance, Claude Mythos Preview was announced on April 7, 2026, and Anthropic limited it to a defensive coalition called Project Glasswing. In an earlier update reported by SecurityWeek, Mythos Preview had flagged more than 23,000 potential vulnerabilities across more than 1,000 projects. External firms had reviewed 1,900 of them and confirmed 1,726, and only 75 critical or high issues had been patched.

Outside firms confirmed 5,674 findings, and upstream projects patched 516

Anthropic says it spent the last six months scanning some of the world's most important software projects and found more than 29,000 candidate vulnerabilities. Only about 6,000 have been reviewed and triaged by hand, and the company writes that it remains "bottlenecked on our human capacity to validate these findings."

The New Stack fills in the numbers behind that bottleneck. The review pipeline relies on six external security research firms, and as of October 2 they had confirmed 5,674 of the 6,123 findings they reviewed. Anthropic had sent 6,157 findings to maintainers. A total of 584 CVE and GitHub Security Advisory identifiers had been issued, with some findings getting both, and 516 vulnerabilities had been patched upstream.

Nearly 5,000 unverified reports went out because maintainers asked for them

The fast track came from maintainers. Anthropic says projects that got its first reports kept asking for everything it had, unverified reports and proposed patches included, and it has already sent nearly 5,000 of those. The company's argument is about speed: exploits can now be written in minutes, so projects that find and fix bugs faster stand a better chance against attackers hunting for the same weaknesses.

The human-reviewed route stays. Anthropic will keep disclosing verified reports through its coordinated vulnerability disclosure (CVD) process, especially for projects that lack the people to triage reports themselves. Anthropic's published disclosure principles set a 90-day deadline, make human-reviewed reports the default and promise to pace submissions to what maintainers can absorb. The fast track skips that review step.

Alongside the scanner, Anthropic points to two other programs. The Cyber Verification Program gives qualifying security professionals advanced cyber capabilities with fewer blocking classifiers. Claude for OSS hands out free Claude Max 20x subscriptions for fixing vulnerabilities and improving projects.

Each report ships with a reproducer, a bisection and, when possible, a patch

OSS Scanner is modeled on Google's OSS-Fuzz, which scans open-source code with fuzzers: programs that throw malformed input at software until something breaks. Anthropic swaps the fuzzers for its strongest language models and runs scans on a schedule, at no cost to the project. Claude Security, the company's general-access scanning and patching product, remains aimed at enterprises.

Each report includes a self-contained reproducer and an explanation of the bug. Where possible, it also includes a bisection, which means testing older versions of the code and halving the range each time until the commit that introduced the bug turns up. A candidate patch is attached when one is available. Think of a plumber who shows up having found the leak, with the date the pipe went in and the replacement part already in the van.

The capability behind the scanner has moved quickly. Anthropic says that on CyberGym, an academic benchmark for finding vulnerabilities, LLMs went from catching under 20% of vulnerabilities at the start of last year to over 85% this year. Over the same period, it says, maintainers stopped getting mostly slop and started getting high-quality reports.

In an early test, 85 of 97 serious findings met the disclosure bar

To check an early version, Anthropic had the penetration testers who review its CVD findings look at 97 critical and high-severity vulnerabilities the scanner found across 48 projects. Of these, 85 (88%) met the bar for CVD. Of the other 12, 11 were real bugs that duplicated known issues or other findings, and one was a false positive.

The pipeline was also tested with dozens of projects over several weeks. That produced hundreds of bug reports, including several vulnerabilities Anthropic chained into unauthenticated remote code execution exploits. Todd Ouska of wolfSSL said that of the 74 reports his team received, all but two were valid and five became CVEs. Daniel Stenberg said the scanner found one of the worst curl vulnerabilities reported in the last few years.

Anton Arapov of OpenSSL Corporation said the reports, raw model output included, were as good as human reports and sometimes better. Noah Misch of PostgreSQL said several came with fixes his team could use nearly as-is. Eddie Kohler of HotCRP praised how well the reports understood the project's complex permission model.

The validation sample covers just 97 critical and high findings from early scanner output. As The New Stack notes, it says little about lower-severity bugs or about how the scanner performs at scale, and Anthropic admits maintainers have reported inflated severity ratings and misread threat models. In our view, the slow step has moved to maintainers, who per The New Stack still test, backport and ship every fix, and 516 patches against 5,674 confirmed findings show how long that queue already is.

Which projects get scanned next

Core maintainers can enroll by submitting a PR to Anthropic's GitHub repo using the standard project template. Eligibility follows criteria similar to OSS-Fuzz, meaning a "critical impact on infrastructure and user security," and decisions are made case by case. Anthropic has not said how many projects it will accept or how often each one will be scanned. The number to watch is the gap between confirmed and patched findings on the dashboard.

Related stories

  1. Anthropic's free OSS Scanner skips human review on purpose
  2. Anthropic pulls live internet from all its internal evals
  3. Anthropic's test agents filled out US visa applications
  4. Anthropic model faked a murder tip to Philadelphia police
  5. Anthropic's new usage policy bans cruelty toward Claude
  6. Anthropic adds offensive tiers for verified pentesters

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.