Skip to main content
Back to timeline
AnthropicSource publication:

Anthropic launches OSS Scanner: free vulnerability scanning of open-source code with its strongest models, where 85 of 97 high-severity findings met its disclosure bar in early validation

Synopsis

Anthropic is launching OSS Scanner, an opt-in vulnerability scanner for the open-source ecosystem that provides free, periodic scans by its strongest language models (including Claude Mythos) with fully model-generated output and no human review; in early validation, expert penetration testers reviewed 97 critical and high-severity vulnerabilities across 48 projects, of which 85 (88%) met the bar for its coordinated vulnerability disclosure process and only one was invalid.

AI-generated editorial illustration: Launching an opt-in vulnerability-finding service for open-source software

Interpretation

The service turns language-model vulnerability discovery into free, periodic, opt-in security audits for open-source projects, with output that is fully model-generated and receives no human review or triage. Previously the team used Claude to find vulnerabilities during Project Glasswing and disclosed human-verified reports through its coordinated vulnerability disclosure process; OSS Scanner adds an optional fast-track that lets maintainers receive all reports and candidate patches before validation. The text states reports are generated by the team's strongest models, including Claude Mythos, and that the pipeline was validated over several weeks with dozens of open-source projects, whose initial disclosures contained hundreds of bug reports.

Early validation indicates model-generated critical and high-severity reports largely withstand expert review: 85 of 97 vulnerabilities (88%) met the bar for the team's coordinated vulnerability disclosure process. The check was performed by the expert penetration testers who review the team's coordinated vulnerability disclosure findings, across 48 projects, providing human-review evidence for the credibility of model-generated vulnerability reports. Of the remaining 12, eleven were real but duplicated known issues or other findings from the scan, and only one was invalid; the text also notes maintainers seldom reported a high or critical finding as invalid, though some said severity ratings can be inflated or the scanner misunderstood the project's threat model.

Reports are designed to be directly actionable: each contains a self-contained reproducer, an explanation of the vulnerability including a bisection to determine when the bug was introduced where possible, and a candidate patch when available. This lets maintainers evaluate and fix issues without first going back and forth with the disclosing party, and the text says initial disclosures included multiple vulnerabilities that could be chained to unauthenticated remote code execution exploits. This description comes from the account of early validation across dozens of projects and hundreds of bug reports; no per-report statistical distribution is given.

The service responds to a human-validation bottleneck: over the last six months, scanning found more than 29,000 candidate vulnerabilities, but only about 6,000 could be manually reviewed and triaged. The text says maintainers increasingly ask for bulk submission of all unverified reports with proposed patches, and that nearly 5,000 reports have been sent directly to maintainers on request; OSS Scanner productizes that practice as an optional fast-track. These figures are the team's own operational statistics without independent audit; the text also states that the human-verified coordinated vulnerability disclosure process continues, especially for projects without the resourcing to triage reports themselves.

Perspective

The service targets open-source projects meeting criteria similar to OSS-Fuzz's, namely projects with a critical impact on infrastructure and user security, enrolled by core maintainers via a pull request following a standard template, with eligibility decided case by case. It suits maintainers who want all unverified reports and candidate patches quickly and can triage them themselves; for projects without the resourcing to triage reports, the human-verified coordinated vulnerability disclosure process continues. Reports are generated by the strongest models, including Claude Mythos, and can accelerate discovery and remediation, but the text explicitly states reports may be incorrect or invalid.

The early-validation sample of 97 vulnerabilities comes from 48 projects, and it is not yet clear whether that pass rate holds at larger scale or across more types of projects. The text notes some maintainers said severity ratings can be inflated or the scanner misunderstood the project's threat model, but the distribution and frequency of such feedback are not given. How many invalid or duplicate reports a fully model-generated, unreviewed pipeline produces over time, and how maintainer triage burden changes, remain open questions. The text also does not specify scanning frequency, the code scope covered, or report deduplication mechanisms.

Sources