anthropic.com web signal

Anthropic launches OSS Scanner for open-source maintainers

TL;DR

  • OSS Scanner found over 29,000 candidate vulnerabilities in six months; around 6,000 were triaged and nearly 5,000 sent to maintainers.
  • Of 97 critical/high-severity reports reviewed, 85 (88%) met coordinated disclosure standards, 11 duplicated known bugs, and only one was invalid.
  • Reports are fully model-generated without human review and include a reproducer, bisection, and candidate patch; eligible projects enroll via a GitHub PR.

Anthropic's Frontier Red Team has discovered over 29,000 candidate vulnerabilities across open-source projects in the last six months using Claude models, and is now opening the service, called OSS Scanner, to any eligible maintainer who opts in, the company announced.

Of those 29,000 candidates, roughly 6,000 were manually reviewed and triaged, and nearly 5,000 were sent directly to project maintainers upon request. Reports are "fully model-generated, without human review or triage," produced by what Anthropic calls its strongest models "(including Claude Mythos)," and bundle a self-contained reproducer, a bisection locating when the bug was introduced where possible, and a candidate patch.

The validation numbers are the most interesting part. Of 97 critical/high-severity vulnerabilities Anthropic reviewed, 85 (88%) met the coordinated vulnerability disclosure standard, 11 duplicated known issues, and only one was invalid. Anthropic attributes this to a capability jump: LLM vulnerability-finding scores improved from under 20% to over 85% on the CyberGym benchmark.

Participating projects speak for the service. OpenSSL said reports were "as good and sometimes better than what we get from people." wolfSSL told Anthropic that "of the 74 reports we received, all but two were valid, and five became CVEs." curl described one submission as "one of the worst curl vulnerabilities reported in the last few years." PostgreSQL said fast-track access "let us address the newest issues before they reached a GA release." Two of the researchers in our Who's Who directory had already shared the announcement link.

Anthropic flags that reports can be wrong, with severity ratings that "can be inflated or the scanner misunderstood the project's threat model." Core maintainers of eligible projects, defined as those with critical impact on infrastructure and user security, must enroll by submitting a PR to a GitHub repo following the standard project template.

Shared on Bluesky by 2 AI experts