TLDRocket
Sign in

Claude found 29,000 possible bugs in open source. Only 516 have been fixed.

The New Stack Amanda Caswell ● Covered by 6 sources

Claude has flagged 29,000 possible bugs in open source, but only 516 have been fixed. Anthropic’s scanner is outrunning human review, and maintainers are getting the reports straight away.

Based on reporting by The New Stack, Amanda Caswell — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic’s new OSS Scanner is doing something awkwardly impressive: it’s finding possible security bugs far faster than the company can get humans to sort through them. Over six months, scans of widely used open source projects produced more than 29,000 candidate vulnerabilities. By October 2, the review pipeline had only made it through about 6,000 of them.

The numbers from Anthropic’s disclosure dashboard show the bottleneck clearly. Outside security firms had confirmed 5,674 of 6,123 reviewed findings as valid, but only 516 vulnerabilities had been patched upstream. Anthropic says it sent 6,157 findings to maintainers, and 584 CVE and GitHub Security Advisory identifiers were issued, though some findings earned both. Roughly 23,000 candidates were still waiting for review.

To keep the backlog from becoming the whole story, Anthropic is also offering an optional fast-track. For eligible projects, it runs periodic scans with its top models, including Claude Mythos, and sends the findings directly to maintainers without first validating them internally. The company says some projects asked for everything after receiving the first batch, and it has already forwarded nearly 5,000 unvalidated reports to those that wanted them.

Anthropic says its early sample looks strong. Security testers reviewed 97 critical and high-severity findings from an early scanner version across 48 projects. Eighty-five were suitable for disclosure, 11 of the remaining 12 were real bugs tied to known issues or other scan findings, and only one was a false positive. But that was an early slice, not the full flood of 29,000 candidates, and Anthropic has already acknowledged cases where the scanner overstated severity or misunderstood a project’s threat model.

The reports themselves seem to be the product’s real edge. Anthropic says they can include a reproducer, a bisection-based explanation of where a bug was introduced, and sometimes a candidate patch. OpenSSL Corporation’s Anton Arapov said the reports matched or beat what the project gets from human researchers. Todd Ouska of wolfSSL said 72 of 74 reports his team received were valid. PostgreSQL committer Noah Misch said some fixes were nearly ready to ship as-is. And cURL’s Daniel Stenberg, who spent last year complaining about AI-generated bug bounty noise, says OSS Scanner found several issues in curl, including one of the worst vulnerabilities reported there in years.

Anthropic is keeping the service narrow on purpose. It’s limited to established open source projects that can handle the load, with OSS-Fuzz-style eligibility checks and core maintainer verification. That’s sensible. The awkward part is that the company’s models are now good enough to create a new kind of backlog: not finding bugs, but proving them.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI security everyone keeps missing: discovery is cheap, verification is the bill. Anthropic’s setup is basically a firehose with a nice label on it, and that’s still better than the usual slop storm hitting maintainers. The open-source world doesn’t need more mystery alerts; it needs fewer, better ones, delivered by systems that can be triaged without turning a volunteer project into a second job.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.