ResearchResearch 5 min read

Anthropic Launches Free OSS Scanner for Open-Source Vulnerabilities

Anthropic launched OSS Scanner on 8 October 2026, a free opt-in service that uses its strongest models to find vulnerabilities in eligible open-source projects.

PC

PromptCrates Editorial

Staff Writer

0 0
Anthropic Launches Free OSS Scanner for Open-Source Vulnerabilities

Anthropic launched OSS Scanner on 8 October 2026, an opt-in vulnerability-finding service that uses the company's strongest language models to scan open-source projects at no cost. The Anthropic research post says the service is informed by Project Glasswing, the company's earlier work applying Claude to security research, and that projects which enrol will receive thorough, periodic scans. Over the last six months Anthropic says it discovered more than 29,000 candidate vulnerabilities and manually reviewed about 6,000 of them, while maintainers who asked for bulk submissions have received nearly 5,000 reports even when those findings were not yet human-validated.

Why Anthropic is opening a fast track for maintainers

Anthropic frames the launch around a capacity bottleneck. Human reviewers cannot keep pace with model-generated findings, yet attackers can develop exploits in minutes once a weakness is known. The company will keep sending human-verified reports through its coordinated vulnerability disclosure process, especially for projects that lack triage staff, and it is adding OSS Scanner as an optional fast track for teams that want raw model reports as soon as they are available. Outputs from the scanner are fully model-generated, without human review or triage, which Anthropic says enables faster and more frequent scanning while also meaning some reports may be incorrect.

The design is explicitly compared to Google's OSS-Fuzz, which scans open-source software with fuzzers. Anthropic positions Claude Security as the general-access product for enterprises defending their own systems, and OSS Scanner as the free audit lane for open-source projects that meet eligibility rules similar to OSS-Fuzz: critical impact on infrastructure and user security, with decisions made case by case. Core maintainers enrol by submitting a pull request to Anthropic's GitHub enrolment repo using a standard project template.

Early results from PostgreSQL, OpenSSL, wolfSSL and HotCRP

Anthropic published maintainer quotes from early testing. Noah Misch of PostgreSQL said an unusually high fraction of findings uncovered PostgreSQL defects and that fast-track access let the project address newest issues before a general-availability release. Anton Arapov of OpenSSL Corporation said reports that arrive with a real exploit attached are effectively "job done" for an engineer who can verify immediately. Todd Ouska of wolfSSL said that of 74 reports received, all but two were valid and five became CVEs, with attached patches fitting existing verify-and-fix workflows. Eddie Kohler of HotCRP praised thorough reports that understood the project's complex permission model.

To validate an early pipeline, Anthropic asked expert penetration testers who already review its CVD findings to check 97 critical and high-severity scanner results across 48 projects. Of those, 85, or 88%, met the bar for the CVD process. Of the remaining 12, eleven were real but duplicated known issues or other scan findings, and only one was judged invalid. Anthropic notes that some maintainers still say severity ratings can be inflated or that the scanner misunderstood a project's threat model, and it says it will keep refining the system from feedback as models improve. Initial disclosures during testing included hundreds of bug reports and multiple vulnerabilities chained to unauthenticated remote code execution, each with a self-contained reproducer, explanation, bisection when possible, and a candidate patch when available.

How OSS Scanner relates to Anthropic's cyber work

The launch sits beside other Anthropic cyber programmes mentioned in the same post: a Cyber Verification Program that makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals, and Claude for OSS free Claude Max 20x subscriptions to help remediate vulnerabilities. PromptCrates has previously covered related Anthropic security threads, including Claude Security and Mythos enterprise positioning, Mythos alignment and cyber incidents, and broader frontier-lab cyber capability gating. Those stories describe capability, incident response and enterprise tooling; OSS Scanner is specifically about giving high-impact open-source maintainers model-speed findings without a consulting invoice.

Anthropic also cites CyberGym, an academic vulnerability-finding benchmark, to argue that language models have moved from finding under 20% of vulnerabilities early last year to more than 85% this year, which it says has shifted maintainer experience from mostly low-quality model reports toward higher-quality ones. That benchmark claim is Anthropic's citation of external research progress rather than a new CyberGym release dated to this post.

What open-source teams should decide next

Eligible maintainers face a practical choice rather than a marketing slogan. Accepting model-generated reports can shorten the gap between discovery and patching, especially when a report includes a reproducer and a draft fix, but it also adds triage load and the risk of chasing invalid or duplicated issues. Anthropic's own 88% CVD-bar figure and the wolfSSL experience suggest the signal can be high for some projects, while the company's warning about severity inflation and threat-model mistakes is a reason to keep humans in the loop even on the fast track. Projects that cannot absorb bulk noise may prefer to wait for Anthropic's slower, human-verified CVD channel.

Enrolment through a GitHub pull request keeps the process public and reviewable, which fits open-source norms better than a private web form. Teams that join should plan how they will label scanner findings in issue trackers, how quickly they will acknowledge reports that include working exploits, and whether they want Anthropic to keep sending everything or only findings above an agreed severity. The 8 October launch does not claim that every open-source repo will be scanned; it opens a voluntary lane for projects Anthropic judges critical, and it leaves ordinary application security buyers on the Claude Security product path.

researchAnthropicopen sourcecybersecurityClaude

Related articles