Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them.
Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing.
The backdrop here is a genuinely fast shift in what these models can actually do. On CyberGym, an academic benchmark for vulnerability finding, LLMs went from catching under 20 percent of known flaws at the start of last year to over 85 percent this year. That’s not incremental progress, that’s a different category of tool entirely.
Over the past six months, Anthropic tested its latest AI models on some of the most widely used open-source software and found more than 29,000 possible vulnerabilities. Its experts have had time to manually check and confirm only about 6,000 of them. That is already a large number of real bugs, but the backlog shows that the main limit is not the AI’s ability to find flaws. It is the time people need to check the results.
“Over the last six months, we’ve used our latest models to scan for vulnerabilities in some of the world’s most important software projects. We have discovered over 29,000 candidate vulnerabilities, but have only been able to manually review and triage approximately 6,000 of these.” reads the announcement. “While 6,000 vulnerabilities is significant, we remain bottlenecked on our human capacity to validate these findings.”
Because of this, some maintainers asked Anthropic to send them all the findings, even those that had not been confirmed. Anthropic has already shared nearly 5,000 unverified reports, along with suggested fixes, with maintainers who requested them. When attackers can develop an exploit in minutes, waiting for every report to be checked by a human before sharing it may create more risk than sending it early, as long as maintainers understand that the findings still need verification.
The model is borrowed loosely from Google’s OSS-Fuzz, which has spent years scanning open source code with fuzzers. OSS Scanner swaps fuzzing for Anthropic’s strongest models, including Claude Mythos, and runs fully automated, with no human review before a report goes out. That trade-off is explicit: faster, more frequent scanning, in exchange for accepting that some reports will be wrong.
Each report includes the tools needed to understand and reproduce the bug, a clear explanation, and a suggested fix when available. If possible, it also identifies the code change that introduced the flaw. During testing, the scanner combined several vulnerabilities to create working exploits that allowed attackers to run code remotely without logging in. These attacks worked against real software projects, not just in theory.
The quotes Anthropic collected read less like a vendor pitch and more like genuine relief. Daniel Stenberg of curl said the scanner helped surface multiple issues worth fixing, including what he called one of the worst curl vulnerabilities reported in years. Todd Ouska at wolfSSL reported that of 74 findings, all but two turned out valid, and five became full CVEs.
Anton Arapov from OpenSSL made the comparison explicit, saying early AI vulnerability reports from roughly eighteen months ago, before Project Glasswing, were genuinely bad, while what Anthropic sends now holds up against reports from actual human researchers. That’s a meaningful jump for anyone who remembers how much useless AI-generated noise flooded maintainer inboxes not that long ago. The scanner went from being the thing maintainers dreaded opening to the thing they’re asking for more of.
Anthropic ran its own accuracy check before wider rollout, having expert penetration testers examine 97 critical and high severity findings across 48 projects.
“To validate an early version of OSS Scanner, we asked the expert penetration testers who review our CVD findings to check 97 critical and high-severity vulnerabilities from the scanner across 48 projects.” continues the announcement. “Of these, 85 (88%) met the bar for our CVD process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the scan, and only one was invalid, i.e. a “false positive.” “
Of the remaining 12, 11 turned out to be real but duplicates of already-known issues, and exactly one was a genuine false positive.
That’s a strong hit rate for a fully unreviewed pipeline, and Anthropic is upfront that it won’t always be perfect. Some maintainer feedback flagged inflated severity ratings or cases where the scanner misread a project’s specific threat model. Fair enough, no automated system gets context perfectly right every time, but one false positive out of 97 critical findings is a number most human-run bug bounty programs would be happy to hit.
The framing Anthropic uses is blunt: exploits can now be built in minutes, so the projects that find and patch vulnerabilities faster are the ones that actually stay ahead of attackers racing toward the same weaknesses. That’s not marketing language, it’s a genuine description of where the defender-attacker timeline has moved. Giving maintainers, especially small ones without dedicated security teams, free access to that speed is a real shift in who gets to play defense effectively.
Core maintainers of eligible projects can apply through a GitHub PR, judged against criteria similar to what OSS-Fuzz already uses, based on how critical the project is to broader infrastructure and user security. Full research writeup, maintainer feedback, and enrollment details:
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Anthropic)

