Compare AIFind AIAI NewsAI How-To
About Us
PrivacyTermsFAQContactContact
AIB Inc.Company info
© 2026 AIB Inc.

Anthropic Launches OSS Scanner

Anthropic Launches OSS Scanner

Anthropic Research·Friday, October 9, 2026
  • •Anthropic launched OSS Scanner, offering opt-in, no-cost periodic vulnerability scans for open-source projects.
  • •Models exceeded 85% on CyberGym this year; Anthropic found over 29,000 candidate vulnerabilities in six months.
  • •Testers found 85 of 97 critical and high-severity findings met Anthropic’s disclosure bar across 48 projects.
  • •Anthropic launched OSS Scanner, offering opt-in, no-cost periodic vulnerability scans for open-source projects.
  • •Models exceeded 85% on CyberGym this year; Anthropic found over 29,000 candidate vulnerabilities in six months.
  • •Testers found 85 of 97 critical and high-severity findings met Anthropic’s disclosure bar across 48 projects.
  • •Anthropic launched OSS Scanner, offering opt-in, no-cost periodic vulnerability scans for open-source projects.
  • •Models exceeded 85% on CyberGym this year; Anthropic found over 29,000 candidate vulnerabilities in six months.
  • •Testers found 85 of 97 critical and high-severity findings met Anthropic’s disclosure bar across 48 projects.
  • •Anthropic launched OSS Scanner, offering opt-in, no-cost periodic vulnerability scans for open-source projects.
  • •Models exceeded 85% on CyberGym this year; Anthropic found over 29,000 candidate vulnerabilities in six months.
  • •Testers found 85 of 97 critical and high-severity findings met Anthropic’s disclosure bar across 48 projects.

Anthropic launched OSS Scanner on October 8, 2026, an opt-in vulnerability scanner that uses its strongest language models to scan open-source projects at no cost. Projects that enroll receive periodic security scans. Anthropic says the service was informed by its use of Claude to find vulnerabilities during Project Glasswing. Unlike its existing coordinated vulnerability disclosure process, the new fast-track sends model-generated findings to maintainers without human review or triage, so some reports may be incorrect or invalid.

Anthropic cited a rise in language models’ performance on CyberGym, an academic vulnerability-finding benchmark: models went from finding under 20% of vulnerabilities at the beginning of last year to over 85% this year. Over the previous six months, Anthropic’s latest models identified over 29,000 candidate vulnerabilities in major software projects, while its staff manually reviewed and triaged approximately 6,000. The company said its capacity to validate findings remains a bottleneck. Maintainers have asked to receive unverified reports with proposed patches; Anthropic has sent nearly 5,000 reports this way. It said exploits can now be developed in minutes.

Anthropic will continue human-verified disclosures through its existing coordinated vulnerability disclosure process, particularly for projects without resources to triage reports. OSS Scanner offers an optional fast-track for projects that want reports as soon as they are generated. Anthropic said the scanner is intended for open-source projects, while Claude Security is its general-access code scanning and patching product for enterprises. The scanner’s reports may include a reproducer, an explanation and, where possible, a bisection identifying when a bug was introduced and a candidate patch.

Anthropic tested the pipeline with dozens of open-source projects over several weeks. Initial disclosures included hundreds of bug reports, among them vulnerabilities chained into unauthenticated remote code execution exploits. In a separate evaluation, expert penetration testers assessed 97 critical- and high-severity findings across 48 projects: 85 (88%) met the bar for Anthropic’s disclosure process. Of the remaining 12, 11 were real but duplicated known issues or other scan findings, and one was invalid. Anthropic said some maintainers found severity ratings inflated or threat models misunderstood, and it will refine the system based on feedback and model improvements.

Maintainers of eligible projects can enroll by submitting a pull request to Anthropic’s GitHub repository using its project template. Eligibility follows criteria similar to OSS-Fuzz, including critical impact on infrastructure and user security, with decisions made case by case. Anthropic also pointed security professionals to its Cyber Verification Program and said Claude for OSS offers free Claude Max 20x subscriptions to help maintainers remediate vulnerabilities and improve projects.

Anthropic launched OSS Scanner on October 8, 2026, an opt-in vulnerability scanner that uses its strongest language models to scan open-source projects at no cost. Projects that enroll receive periodic security scans. Anthropic says the service was informed by its use of Claude to find vulnerabilities during Project Glasswing. Unlike its existing coordinated vulnerability disclosure process, the new fast-track sends model-generated findings to maintainers without human review or triage, so some reports may be incorrect or invalid.

Anthropic cited a rise in language models’ performance on CyberGym, an academic vulnerability-finding benchmark: models went from finding under 20% of vulnerabilities at the beginning of last year to over 85% this year. Over the previous six months, Anthropic’s latest models identified over 29,000 candidate vulnerabilities in major software projects, while its staff manually reviewed and triaged approximately 6,000. The company said its capacity to validate findings remains a bottleneck. Maintainers have asked to receive unverified reports with proposed patches; Anthropic has sent nearly 5,000 reports this way. It said exploits can now be developed in minutes.

Anthropic will continue human-verified disclosures through its existing coordinated vulnerability disclosure process, particularly for projects without resources to triage reports. OSS Scanner offers an optional fast-track for projects that want reports as soon as they are generated. Anthropic said the scanner is intended for open-source projects, while Claude Security is its general-access code scanning and patching product for enterprises. The scanner’s reports may include a reproducer, an explanation and, where possible, a bisection identifying when a bug was introduced and a candidate patch.

Anthropic tested the pipeline with dozens of open-source projects over several weeks. Initial disclosures included hundreds of bug reports, among them vulnerabilities chained into unauthenticated remote code execution exploits. In a separate evaluation, expert penetration testers assessed 97 critical- and high-severity findings across 48 projects: 85 (88%) met the bar for Anthropic’s disclosure process. Of the remaining 12, 11 were real but duplicated known issues or other scan findings, and one was invalid. Anthropic said some maintainers found severity ratings inflated or threat models misunderstood, and it will refine the system based on feedback and model improvements.

Maintainers of eligible projects can enroll by submitting a pull request to Anthropic’s GitHub repository using its project template. Eligibility follows criteria similar to OSS-Fuzz, including critical impact on infrastructure and user security, with decisions made case by case. Anthropic also pointed security professionals to its Cyber Verification Program and said Claude for OSS offers free Claude Max 20x subscriptions to help maintainers remediate vulnerabilities and improve projects.

Read original (English)·Oct 8, 2026
Safety & Ethics#anthropic#oss scanner#open source security#vulnerability scanning#cybergym#project glasswing#coordinated vulnerability disclosure#remote code execution