Claude found 29,000 possible bugs in open source, only 516 fixed
Anthropic's OSS Scanner, part of its Cyber Mission, surfaced over 29,000 candidate vulnerabilities in widely used open source projects over six months. Human reviewers worked through about 6,000 findings, confirming 5,674 as valid, but only 516 were patched upstream; roughly 23,000 candidates remain unreviewed.
- Claude surfaced over 29,000 candidate vulnerabilities in six months of scanning
- Of 6,123 reviewed findings, 5,674 were confirmed valid but only 516 were patched
- 584 CVE and GitHub Security Advisory identifiers were issued
- 6,157 reports were sent to maintainers; about 23,000 candidates remain unreviewed
Read next
Security