Published October 11, 2026 · Added October 11, 2026

Anthropic's OSS Scanner fast-tracks unreviewed Claude vulnerability reports to maintainers

The New Stack's Amanda Caswell reports that Anthropic's OSS Scanner, launched as part of its broader Cyber Mission, sends raw Claude vulnerability reports straight to open source maintainers because the models are finding candidate flaws faster than the company's human review pipeline can verify them. Over six months of scanning widely used open source projects the models surfaced more than 29,000 candidates, while the six external security research firms Anthropic relies on had worked through only about 6,000: 5,674 of 6,123 reviewed findings were confirmed valid, 6,157 findings were sent to maintainers, 584 CVE and GitHub Security Advisory identifiers were issued, and only 516 vulnerabilities had been patched upstream as of October 2, leaving roughly 23,000 candidates unreviewed. Anthropic calls the arrangement an optional fast track and has already sent nearly 5,000 unvalidated reports to maintainers who asked for them, with disclosure terms that give those maintainers no 90-day clock unless the company later validates a finding through its standard program; a check of 97 critical and high-severity findings from an early scanner version across 48 projects cleared 85 for disclosure and found only one false positive, though Anthropic has acknowledged inflated severity ratings and reports that misunderstood a project's threat model. Amid the criticism of AI-generated report floods, OpenSSL Corporation's Anton Arapov said the reports matched or beat what the project gets from human researchers, wolfSSL founder Todd Ouska said 72 of 74 reports were valid and five became CVEs, PostgreSQL committer Noah Misch said several arrived with fixes usable "nearly as-is", and curl founder Daniel Stenberg, who shut down curl's bug bounty in January over low-effort AI submissions, said OSS Scanner found multiple curl issues including one of the worst vulnerabilities the project has seen recently. Maintainers still have to test, backport and ship any fix, and Anthropic restricts enrollment to established projects under OSS-Fuzz-style eligibility criteria while offering free Claude Max 20x subscriptions through Claude for OSS.

The New Stack’s Amanda Caswell reports that Anthropic’s OSS Scanner, launched as part of its broader Cyber Mission, sends raw Claude vulnerability reports straight to open source maintainers because the models are finding candidate flaws faster than the company’s human review pipeline can verify them. Over six months of scanning widely used open source projects the models surfaced more than 29,000 candidates, while the six external security research firms Anthropic relies on had worked through only about 6,000: 5,674 of 6,123 reviewed findings were confirmed valid, 6,157 findings were sent to maintainers, 584 CVE and GitHub Security Advisory identifiers were issued, and only 516 vulnerabilities had been patched upstream as of October 2, leaving roughly 23,000 candidates unreviewed. Anthropic calls the arrangement an optional fast track and has already sent nearly 5,000 unvalidated reports to maintainers who asked for them, with disclosure terms that give those maintainers no 90-day clock unless the company later validates a finding through its standard program; a check of 97 critical and high-severity findings from an early scanner version across 48 projects cleared 85 for disclosure and found only one false positive, though Anthropic has acknowledged inflated severity ratings and reports that misunderstood a project’s threat model. Amid the criticism of AI-generated report floods, OpenSSL Corporation’s Anton Arapov said the reports matched or beat what the project gets from human researchers, wolfSSL founder Todd Ouska said 72 of 74 reports were valid and five became CVEs, PostgreSQL committer Noah Misch said several arrived with fixes usable “nearly as-is”, and curl founder Daniel Stenberg, who shut down curl’s bug bounty in January over low-effort AI submissions, said OSS Scanner found multiple curl issues including one of the worst vulnerabilities the project has seen recently. Maintainers still have to test, backport and ship any fix, and Anthropic restricts enrollment to established projects under OSS-Fuzz-style eligibility criteria while offering free Claude Max 20x subscriptions through Claude for OSS.

Read the original story.

Source: The New Stack