Anthropic's bug scanner floods open source with 29,000 findings, but fixes lag far behind
The company's OSS Scanner finds vulnerabilities faster than human researchers can validate them, creating a backlog that exposes tensions between AI-powered discovery and the practical work of patching code.

Anthropic launched its OSS Scanner last week as part of a broader Cyber Mission, but the tool has surfaced a fundamental mismatch within the company's security research operation: Claude can identify potential vulnerabilities at a pace that outstrips the capacity of human teams to verify them.
Over a six-month scanning campaign targeting some of the most widely deployed open source projects, Anthropic's models identified more than 29,000 candidate vulnerabilities. The company's human review pipeline, which depends on six external security research firms to reproduce and triage findings, has processed only about 6,000 of them.
A public disclosure dashboard quantifies the bottleneck. As of October 2, the external security firms had validated 5,674 of the 6,123 findings they examined as genuine vulnerabilities, yet only 516 had been patched in upstream repositories. Anthropic transmitted 6,157 findings to maintainers, resulting in 584 CVE and GitHub Security Advisory identifiers, with some findings receiving both designations. Approximately 23,000 candidates remain unreviewed.
Claude is finding potential vulnerabilities faster than human researchers can verify them.
How the fast track works
Rather than requiring maintainers to wait while Anthropic works through its backlog, the company is offering eligible projects complimentary, recurring scans powered by its most advanced models, including Claude Mythos. These findings reach maintainers directly, bypassing Anthropic's internal validation step.
Anthropic observed that projects receiving initial reports frequently requested access to all remaining findings, prompting the company to send nearly 5,000 unvalidated reports to maintainers who asked for them. The company now refers to this arrangement as an "optional fast-track."
Bypassing the backlog
Professional penetration testers responsible for vetting coordinated disclosures reviewed 97 critical and high-severity findings from an early scanner version across 48 projects. Eighty-five met the threshold for disclosure, while 11 of the remaining 12 were genuine bugs that either duplicated known issues or overlapped with other scan results. Just one was a false positive.
These metrics reflect the scanner's early performance, not the 29,000 candidates from Anthropic's separate disclosure initiative. The sample provides limited insight into lower-severity findings or how the scanner scales. In its technical announcement, Anthropic acknowledged that maintainers have flagged inflated severity classifications and instances where the scanner misinterpreted a project's threat model.
What maintainers are reporting
These reports distinguish themselves from standard SAST tool output through their presentation. Anthropic includes a self-contained reproducer, an explanation that identifies where the bug entered the code through bisection when feasible, and a candidate patch when the model generates one. Anton Arapov, director of OpenSSL Corporation, stated that the reports Anthropic delivered, including raw model output, matched and occasionally surpassed what the project receives from human researchers. He noted that a report containing a working exploit represents "basically job done for an engineer as you can verify it right away."
Todd Ouska, founder of wolfSSL, indicated that 72 of the 74 reports his team received were legitimate, with five becoming CVEs. Noah Misch, a PostgreSQL committer, reported that several reports arrived with fixes the project could apply "nearly as-is." Misch also credited fast-track access with enabling PostgreSQL to address emerging issues before they appeared in a general availability release.
The strongest endorsement came from Daniel Stenberg, founder of The cURL Project, who spent the previous year publicly objecting to waves of AI-generated noise flooding his project's bug bounty, which curl discontinued in January. He now states that OSS Scanner uncovered multiple issues in curl, including one of the most severe vulnerabilities the project has encountered in recent years.
Anthropic constructs each project in an isolated virtual machine and disables internet connectivity before scanning starts. Reports travel directly to maintainers via email, and they retain the ability to pause or withdraw at any moment. The GitHub repository houses enrollment and configuration utilities, though not the scanner itself.
Finding bugs versus fixing them
A reproducer and proposed patch can accelerate the process, but maintainers must still validate the fix, manage backports, and deploy it, sometimes accepting that the change will alter behavior that users depend on—a decision OpenSSH's maintainers made when they intentionally disabled two features for security reasons.
Anthropic has restricted access to mature open source projects possessing the infrastructure to absorb higher volumes of vulnerability reports. Projects must satisfy OSS-Fuzz-style eligibility standards, and Anthropic verifies that the applicant is a core maintainer. The company also requires participating projects to remain current with high- and critical-severity vulnerabilities already disclosed to them.
Who gets OSS Scanner access?
The service targets projects equipped to manage this workload. Eligibility adheres to OSS-Fuzz-style criteria for widely used, security-critical open source software. Anthropic confirms that applicants hold core maintainer status, and its FAQ specifies that participating projects should already be managing verified high- and critical-severity reports.
The disclosure framework permits participating maintainers to proceed at their own pace. Unvalidated scanner findings are not subject to a 90-day disclosure window. However, a report that Anthropic later validates through its standard program can be disclosed 90 days after maintainers are notified that a human has confirmed it.
Anthropic indicates it may eventually impose a disclosure period on certain high-severity scanner findings after providing projects with advance notice and an opportunity to decline.
Eligible maintainers can obtain free Claude Max 20x subscriptions through Claude for OSS. The goal is to assist projects in managing the expanding stream of findings, but complimentary Claude access does not expand the time maintainers have available to review and release fixes. As other AI-assisted coding initiatives have demonstrated, code that passes compilation can still harbor defects that require human scrutiny.