Anthropic Opens Free Claude Vuln Scanner to OSS Maintainers
TL;DR
- Anthropic's own validation shows 88% of critical/high-severity candidate vulnerabilities met CVD standards, giving findings credibility beyond a marketing claim.
- Over 29,000 candidate vulnerabilities surfaced in six months of scanning; 584 received CVE advisories by October 2026.
- Anthropic waived the standard 90-day disclosure clock over false-positive concerns, a concession not typical in coordinated vulnerability programs.
Penetration testers reviewed 97 high- and critical-severity findings produced by Anthropic's new OSS Scanner across 48 open-source projects, Help Net Security reports. Eighty-five cleared coordinated-disclosure criteria. Eleven were genuine but already known. One was invalid.
The service builds on an earlier internal effort called Project Glasswing and sends AI-generated vulnerability reports straight to maintainers with no prior human triage. Anthropic's own line about the trade-off is flat: "We can't guarantee the scanner will be perfect." Unvalidated findings do not carry a mandatory disclosure deadline unless Anthropic later validates them through its coordinated-disclosure program, which triggers a 90-day clock.
The pitch comes with an endorsement from Anton Arapov of OpenSSL Corporation: "Early AI reports about 18 months ago, before Project Glasswing, were appalling. The reports we received from Anthropic, raw model output included, were as good and sometimes better than what we get from people. Particularly when a report comes with a real exploit attached, that's basically job done for an engineer as you can verify it right away."
According to Anthropic's own announcement, the company has identified more than 29,000 candidate vulnerabilities in critical open-source projects and reported a little more than 6,000 to maintainers; it puts the scanner's success rate above 85%, up from under 20% early last year. Core maintainers of established, infrastructure-critical projects apply through the OSS Scanner GitHub repo and can pause or exit at any time.
The launch lands a day after our coverage of Anthropic's Cyber Mission with 11 founding partners, part of a wider run of Anthropic security moves on our tracker.
What others are reporting
-
Anthropic Read →
First-party post names PostgreSQL, OpenSSL, wolfSSL, HotCRP, and curl as participants and provides the 88% validation rate on high-severity findings.
Projects that join will receive thorough, periodic security scans by our strongest models at no cost.
-
The Hacker News Read →
Adds the live enrollment count (116 pull requests submitted), the 584 CVE advisory figure, and confirms Anthropic's atypical no-90-day-clock disclosure policy.
Unlike traditional vulnerability programs, Anthropic does not impose an immediate 90-day disclosure period on OSS Scanner findings, due to concerns about false positives.
-
Cyber Security News Read →
Details the isolated VM architecture: internet enabled for dependency install, removed before audit begins; enrollment requires Dockerfile plus optional threat_model.md for scope-setting.
OSS Scanner builds on its work with Project Glasswing. The company says it had reviewed more than 6,000 vulnerability reports by October 2026 through its existing disclosure process.
-
Startup Fortune Read →
Unique scrutiny angle: Claude Code is linked to South Korean bank breaches, and Anthropic has not disclosed retention or training-use policy for scanned code.
Claude Code has now been named, directly or by association, in breaches touching some of South Korea's largest banks.
Originally reported by helpnetsecurity.com
Read the original article →Original headline: Anthropic Launches OSS Scanner Offering Free Claude-Powered Vuln Audits to Open-Source Maintainers