
News
Anthropic opens OSS Scanner, an opt-in service that sends unreviewed model bug reports
On Oct. 8, 2026, Anthropic launched OSS Scanner, a free opt-in service that sends eligible open-source projects fully model-generated vulnerability reports, including reproducers and, when available, candidate patches, without human review.
Searcher → Analyst → Writer → Editor · subagentic-20261009-0800
Anthropic’s Frontier Red Team on Oct. 8, 2026 launched OSS Scanner, a free opt-in vulnerability scanner for open-source software. Projects that join receive periodic security scans from the company’s strongest models, including Claude Mythos, at no cost. The reports are fully model-generated, without human review or triage.
Anthropic says skipping review is what makes faster, more frequent scanning possible. It also means reports can be incorrect or invalid. Each report is supposed to include a self-contained reproducer, an explanation of the vulnerability, including a bisection of when the bug was introduced where possible, and a candidate patch when one is available.
A fast track beside human review
The company ties the launch to a rapid gain in model vulnerability-finding. On CyberGym, an academic benchmark, it says large language models went from finding under 20% of vulnerabilities at the beginning of last year to finding over 85% this year.
Over the previous six months, Anthropic says it scanned some of the world’s most important software projects with its latest models and discovered over 29,000 candidate vulnerabilities. Staff manually reviewed and triaged approximately 6,000. Human validation, it says, remains the bottleneck.
Anthropic will keep disclosing human-verified reports through its existing coordinated vulnerability disclosure process, especially for projects that lack the resourcing to triage reports themselves. OSS Scanner is the optional fast track for maintainers who want findings as soon as they are available.
That path already has a precedent in Anthropic’s own disclosures. The company says maintainers who received first reports have, with increasing frequency, asked for a bulk submission of unverified reports with proposed patches. To date, it has sent nearly 5,000 reports directly to maintainers after they asked to receive everything Anthropic had, even if it was not validated. Anthropic argues that because exploits can now be developed in minutes, projects that find and fix weaknesses faster are better placed against attackers racing the same bugs. The post does not describe how those exploits are built.
What the early scans produced
Anthropic says it spent several weeks validating the pipeline with dozens of open-source projects. Those initial disclosures contained hundreds of bug reports, including multiple vulnerabilities the team was able to chain to unauthenticated remote code execution affecting those projects. The announcement does not publish the reproducers.
Noah Misch of PostgreSQL said an unusually high fraction of findings uncovered PostgreSQL defects, that several reports came with fixes the project can use nearly as-is, and that fast-track access let them address the newest issues before a GA release. Anton Arapov of OpenSSL Corporation said early AI reports about 18 months ago, before Project Glasswing, were appalling, while the Anthropic reports, raw model output included, were as good and sometimes better than reports from people, particularly when a real exploit was attached. Todd Ouska of wolfSSL said that of 74 reports, all but two were valid and five became CVEs, and that attached patches let the reports slot into the existing process to verify and fix issues. Eddie Kohler of HotCRP said the reports were thorough and clear, with a strong understanding of HotCRP’s complex permission model and good bug prioritization. Daniel Stenberg of curl said the scanner helped find multiple issues worth addressing, including one of the worst curl vulnerabilities reported in the last few years.
To check an early version, Anthropic asked the penetration testers who review its disclosure findings to examine 97 critical and high-severity scanner results across 48 projects. Of these, 85 (88%) met the bar for the coordinated disclosure process. Of the remaining 12, 11 were real but duplicated known issues or other findings from the scan, and only one was a false positive. Anthropic says maintainers have seldom told it that a high or critical finding was invalid, though some said severity ratings can be inflated or that the scanner misunderstood a project’s threat model. It does not guarantee the scanner will be perfect, and says it will keep refining the system from maintainer feedback and as models improve.
How projects enroll
Core maintainers of eligible projects enroll by submitting a pull request to Anthropic’s oss-scanner GitHub repository, following the project template. Anthropic says eligibility follows a similar set of criteria to Google’s OSS-Fuzz: projects should have a “critical impact on infrastructure and user security,” and Anthropic will decide case by case. Further guidance is in the extended FAQ linked from the announcement.
The same post separates OSS Scanner from Claude Security, its general-access product for enterprise code scanning and patching. It also points to two other offers: a Cyber Verification Program that makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals, and Claude for OSS, which provides free Claude Max 20x subscriptions to help remediate vulnerabilities and improve open-source projects. Those are not the scanner.
What to do next
If you maintain an eligible project and can triage reports that may be wrong, duplicated, or over-rated, read Anthropic’s Oct. 8 post and the enrollment FAQ, then submit the template pull request. If you cannot absorb unverified volume, Anthropic says the existing human-reviewed disclosure process remains the route for projects without that resourcing.