NEWS

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic's free, opt-in OSS Scanner uses Claude Mythos to audit open-source projects, surfacing 29,000+ candidate bugs and 584 advisories so far.

Dylan H.

News Desk

October 9, 2026
9 min read
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic Opens Free, Model-Only Vulnerability Scanning to Open Source Maintainers

Anthropic on October 8, 2026 launched OSS Scanner, a free, opt-in vulnerability-finding service that runs its most capable AI models against open-source software on a recurring basis. The company says the service is "informed by our experience using Claude to find vulnerabilities during Project Glasswing" — the research effort that previously surfaced thousands of flaws in major codebases using the Claude Mythos model family. OSS Scanner turns that research pipeline into a standing, no-cost service that any eligible maintainer can apply to join.

The launch is one half of what Anthropic calls its broader Cyber Mission, alongside a new Critical Infrastructure Defense Program aimed at operational technology — plants, substations, and water systems — where equipment often cannot be taken offline to patch known flaws for years at a time.


Program Details

AttributeValue
Service nameOSS Scanner
AnnouncedOctober 8, 2026
Cost to maintainersFree
Model(s) usedAnthropic's strongest available models, including Claude Mythos
Inspired byGoogle's OSS-Fuzz
Informed byProject Glasswing (Anthropic's AI vulnerability-research initiative)
EligibilityOpen-source projects with "critical impact on infrastructure and user security," reviewed case by case
How to enrollMaintainer submits a pull request to the anthropics/oss-scanner GitHub repository with a config file and Dockerfile
Human review before deliveryNone — reports are fully model-generated
Report contentsSelf-contained reproducer, vulnerability write-up, bisection to the introducing commit (where possible), candidate patch (when available)
Scale so far (as of October 2, 2026)29,000+ candidate vulnerabilities found over six months; ~6,000 manually triaged by Anthropic; 584 advisories issued
Validity rate88% (85 of 97 critical/high findings validated by independent penetration testers); wolfSSL measured 72 of 74 (≈97%)
Early enrollment interest116 pull requests submitted to the scanner repo as of launch week

How It Works

Enrollment and Eligibility

Participation is entirely voluntary and starts with a project's core maintainers, not outside researchers. To enroll, a maintainer opens a pull request against Anthropic's anthropics/oss-scanner GitHub repository containing a configuration file that specifies the project's git repository URL, a primary contact email, and a Dockerfile describing how to build and run the project in a sandboxed environment. Optional fields include additional contact emails, a project homepage, a GPG public key for encrypted communication, and a threat-model file to steer the scanner toward what actually matters for that codebase.

Anthropic evaluates applications using criteria it describes as similar to Google's OSS-Fuzz program: the project needs meaningful reach into infrastructure or user safety, and acceptance is a case-by-case engineering judgment rather than an automatic gate. Anthropic has said the bar may evolve as the service matures.

No Human Review Before Delivery

The defining — and most debated — design choice in OSS Scanner is that findings reach maintainers without any human triage on Anthropic's side first. That's a deliberate break from Anthropic's existing coordinated-disclosure process, where a security team reviews a model's output before it goes anywhere. Skipping that step is what makes frequent, periodic scanning of many projects at once possible — but Anthropic is explicit that it also means some reports "can still be incorrect." Maintainers become the first human reviewers of each finding, not Anthropic engineers.

Each report is still built to be self-contained: a reproducer the maintainer can run directly, a written explanation of the flaw, a bisection identifying the commit that introduced it where that's determinable, and — when the model can produce one — a candidate patch. Because reports aren't pre-validated, Anthropic doesn't start a mandatory 90-day coordinated-disclosure clock until a finding is manually confirmed real; once that happens, the standard 90-day timeline applies as it would for any other disclosure.

Attribution, Not Obligation

Anthropic isn't requiring anything from maintainers who act on a finding. If a team patches a bug OSS Scanner surfaced, Anthropic asks — but doesn't require — that the commit message include the report's ID, which the company uses to track the service's real-world impact.


Early Results and Partner Feedback

Anthropic spent several weeks validating the pipeline with dozens of open-source projects before the public launch, and says those pilot runs alone produced hundreds of bug reports, including multiple vulnerability chains that reached unauthenticated remote code execution. Maintainers who took part offered specific, attributed feedback in Anthropic's launch post:

ProjectMaintainerTakeaway
PostgreSQLNoah MischReports included fixes usable "nearly as-is"
OpenSSLAnton ArapovRaw model output is "as good and sometimes better than what we get from people"; a report with a working exploit attached is "basically job done for an engineer"
wolfSSLTodd Ouska72 of 74 reports were valid; five became tracked CVEs
curlDaniel StenbergThe scanner helped surface "one of the worst curl vulnerabilities reported in the last few years"

Anthropic did not attach a CVE number or severity rating to the curl claim in its launch post, so that specific flaw cannot yet be independently verified — it is a maintainer quote, not a published advisory.


Why This Matters

The Manual-Triage Bottleneck

Anthropic's own numbers make the case for automation: across six months of scanning major projects, its models flagged more than 29,000 candidate vulnerabilities, but Anthropic's security team could only manually review and triage roughly 6,000 of them. That gap — not a shortage of findings — is what OSS Scanner is built to close. Removing human review from the delivery path doesn't make the underlying analysis better; it removes the bottleneck that was keeping most of it from ever reaching a maintainer.

A Capability Jump Anthropic Says Is Real

Anthropic points to the CyberGym benchmark as evidence the underlying capability has moved quickly: AI models reportedly went from finding fewer than 20% of benchmark vulnerabilities at the start of last year to more than 85% this year. If that trajectory holds, the triage bottleneck OSS Scanner addresses today will only grow — which is also Anthropic's argument for standing up a scalable, opt-in delivery mechanism now rather than later.

Free Access Changes Who Benefits

Unlike Claude Security — Anthropic's enterprise-facing, access-gated scanning and patching product for paying Claude customers — OSS Scanner costs nothing and targets the maintainers of critical open-source infrastructure, many of whom run security-sensitive projects (cryptographic libraries, web servers, databases) with minimal dedicated security staffing. That's the same population Google's OSS-Fuzz has targeted with fuzzing since 2016, and Anthropic is explicit that OSS Scanner is designed in that program's image.


Recommendations

For Open-Source Maintainers

  • Check eligibility before applying. OSS Scanner is scoped to projects with meaningful infrastructure or user-safety impact — review the criteria in the anthropics/oss-scanner repository before submitting a pull request.
  • Treat every report as a lead, not a verdict. Because findings aren't reviewed by Anthropic staff before delivery, validate the reproducer yourself before assuming an issue is real, especially for severity ratings — Anthropic has acknowledged the model can occasionally misjudge a threat model or overstate severity.
  • Use the bisection and candidate patch as a head start, not a merge-ready fix. Partners like PostgreSQL and OpenSSL reported patches close to usable, but maintainer review before merge remains essential.
  • Credit report IDs in commit messages when you patch a finding. It's optional, but it's how Anthropic measures the program's impact, and it helps future researchers trace a fix back to its origin.

For Security Teams Consuming Open-Source Software

  • Don't assume unreviewed reports mean no real risk. A project enrolled in OSS Scanner may be sitting on a genuine, high-severity finding before it's ever publicly disclosed — track security advisories for your critical dependencies closely as adoption grows.
  • Watch for a wave of advisories as the program scales. With 116 projects already applying in launch week alone, expect advisory volume for enrolled dependencies to rise over the coming months.

For Enterprises Evaluating AI Security Tooling

  • Understand the Claude Security vs. OSS Scanner split. Claude Security is the paid, enterprise product with a controlled interface; OSS Scanner is free, open-source-only, and delivers raw model output. They serve different populations and different risk tolerances — don't conflate the two when assessing AI vendor security claims.

Key Takeaways

  1. Anthropic launched OSS Scanner on October 8, 2026 — a free, opt-in vulnerability scanner for open-source projects, powered by its strongest models including Claude Mythos, and explicitly informed by its Project Glasswing research.
  2. Maintainers enroll by submitting a pull request to the anthropics/oss-scanner GitHub repository with a config file and Dockerfile; eligibility criteria mirror Google's OSS-Fuzz, focused on projects with critical infrastructure or safety impact.
  3. Reports are fully model-generated with no human review before reaching maintainers — faster and more frequent scanning, at the cost of occasional false or overstated findings.
  4. In six months of scanning, Anthropic's models surfaced over 29,000 candidate vulnerabilities, of which only about 6,000 could be manually triaged — the exact bottleneck OSS Scanner is designed to remove.
  5. Independent validation puts accuracy around 88% overall, with wolfSSL reporting 72 of 74 reports valid (five became CVEs); partners including PostgreSQL, OpenSSL, and curl gave the pilot positive marks.
  6. OSS Scanner is one piece of Anthropic's broader Cyber Mission, alongside a new Critical Infrastructure Defense Program targeting long-lived operational technology in utilities and industrial environments.

Sources