Skip to content
AI News HubLIVE
Source content · Analysis pending3 min read

Claude found 29,000 possible bugs in open source. Only 516 have been fixed.

Summary

Anthropic’s new OSS Scanner, launched last week as part of its broader Cyber Mission, exposes a problem inside the company’s The post Claude found 29,000 possible bugs in open source. Only 516 have been fixed. appeared first on The New Stack.

SourceThe New Stack AIAuthor: Amanda Caswell
Claude found 29,000 possible bugs in open source. Only 516 have been fixed.
Report an error

The correction channel is not available yet. You can copy the article reference below for later.

Correction instructions
Read article

Anthropic’s new OSS Scanner, launched last week as part of its broader Cyber Mission, exposes a problem inside the company’s security research operation. Claude is finding potential vulnerabilities faster than human researchers can verify them. Over six months of scanning some of the world’s most widely used open source projects, Anthropic’s models surfaced more than 29,000 candidate vulnerabilities. Its human review pipeline, which relies on six external security research firms to reproduce and triage findings, has worked through only about 6,000. A disclosure dashboard puts some numbers behind the problem. As of October 2, outside security firms had confirmed 5,674 of the 6,123 findings they reviewed as valid, but only 516 vulnerabilities had been patched upstream. The company sent 6,157 findings to maintainers, and 584 CVE and GitHub Security Advisory identifiers were issued, though some findings received both. Roughly 23,000 candidates remain unreviewed. Claude is finding potential vulnerabilities faster than human researchers can verify them. How the fast track works Instead of making maintainers wait for its researchers to work through the backlog, Anthropic is giving eligible projects free, periodic scans powered by its top models, including Claude Mythos. The findings go directly to maintainers, without anyone at Anthropic validating them first. Anthropic says projects that received its first reports increasingly asked for everything else it had, and it has already sent nearly 5,000 unvalidated reports to maintainers who requested them. The company now calls the arrangement an “optional fast-track.” Bypassing the backlog Expert penetration testers who vet its coordinated disclosures were asked to check 97 critical and high-severity findings that an early version of the scanner produced across 48 projects. Eighty-five cleared the bar for disclosure, while 11 of the remaining 12 were real bugs that duplicated known issues or other findings from the scan. Only one was a false positive. Those figures describe the scanner’s early output, but not the 29,000 candidates from Anthropic’s separate disclosure program. The sample says little about lower-severity findings or how the scanner will perform at scale. In its technical announcement, Anthropic acknowledged that maintainers have reported inflated severity ratings and cases where the scanner misunderstood a project’s threat model. What maintainers are reporting What separates these reports from a SAST alert queue is how they are packaged. Anthropic says reports include a self-contained reproducer, an explanation that, when possible, identifies where the bug was introduced through bisection, and a candidate patch when the model can produce one. Anton Arapov, director of OpenSSL Corporation, said the reports Anthropic sent, raw model output included, matched and sometimes beat what the project gets from human researchers. He added that a report with a working exploit attached is “basically job done for an engineer as you can verify it right away.” Todd Ouska, founder of wolfSSL, reported that 72 of the 74 reports his team received were valid and five became CVEs. PostgreSQL committer Noah Misch said several reports arrived with fixes the project could use “nearly as-is.” Misch also credited fast-track access with letting PostgreSQL address the newest issues before they shipped in a GA release. But the most pointed endorsement came from The cURL Project founder Daniel Stenberg, who spent last year publicly complaining about the flood of AI-generated slop hitting his project’s bug bounty, which curl shut down in January. He now says OSS Scanner found multiple issues in curl, including one of the worst vulnerabilities the project has seen reported in the last few years. Anthropic builds each project in an isolated VM and cuts off internet access before scanning begins. Reports go directly to maintainers by email, and they can pause or opt out at any time. The GitHub repository contains the enrollment and configuration tools, but not the scanner itself. Finding bugs versus fixing them A reproducer and a proposed patch can save time, but maintainers still have to test the fix, handle backports, and ship it, sometimes knowing the change will break behavior users rely on, which is the tradeoff OpenSSH’s maintainers made when they deliberately broke two features in the name of security. Anthropic is restricting access to established open source projects that have the resources to handle more vulnerability reports. Anthropic is restricting access to established open-source projects with the resources to handle more vulnerability reports. Projects must meet OSS-Fuzz-style eligibility criteria, and Anthropic checks that the person signing up is a core maintainer. The company also expects participating projects to be keeping up with the high- and critical-severity vulnerabilities already reported to them. Who gets OSS Scanner access? The service targets projects equipped to handle that work. Eligibility follows OSS-Fuzz-style criteria for widely used, security-critical open source software. Anthropic verifies that applicants are core maintainers, and its FAQ says participating projects should already be keeping up with verified high- and critical-severity reports. The disclosure terms give participating maintainers room to work at their own pace. Unvalidated scanner findings carry no 90-day clock. However, a report the company later validates through its standard program can be disclosed 90 days after maintainers learn a human has confirmed it. Anthropic says it may eventually attach a disclosure period to some high-severity scanner findings after giving projects notice and a chance to opt out. Eligible maintainers can get free Claude Max 20x subscriptions through Claude for OSS. The idea is to help projects keep up with the growing number of findings, but free access to Claude doesn’t give maintainers more time to review and ship fixes. And as other AI-assisted coding efforts have shown, code that compiles cleanly can still contain problems that human reviewers need to catch. The post Claude found 29,000 possible bugs in open source. Only 516 have been fixed. appeared first on The New Stack.

Key points and analysis

Article intelligence

EngineersAdvanced

Key points

  • AI generation is temporarily unavailable; this entry was preserved with deterministic fallback metadata.
  • Anthropic’s new OSS Scanner, launched last week as part of its broader Cyber Mission, exposes a problem inside the company’s The post Claude found 29,000 possible bugs in open sou…

Highlights and analysis are generated automatically and may contain errors. Check the original source.