Claude found 29,000 possible bugs in open source. Only 516 have been fixed.
Anthropic’s new OSS Scanner, launched last week as part of its broader Cyber Mission, exposes a problem inside the company’s The post Claude found 29,000 possible bugs in open source. Only 516 have been fixed. appeared first on The New Stack .
Anthropic, the developer of the AI chatbot Claude, has launched an open-source scanning tool called OSS Scanner as part of its Cyber Mission. The tool has identified over 29,000 potential vulnerabilities in widely used open-source projects, but only 516 have been fixed. The majority of these findings have yet to be reviewed, with only 6,123 out of the 29,000 reviewed by external security research firms, of which 516 were confirmed as valid.
Anthropic is offering a fast-track option, providing the findings to eligible projects without verification, leading to rapid disclosure. However, this bypasses the current backlog of vulnerabilities. Experts have noted that while the scanner's output is promising, it has also raised concerns about inflated severity ratings and misinterpretation of a project's threat model.
Some maintainers have reported that Anthropic's reports are of high quality, providing necessary context and even proposed fixes. The company has restricted access to established open-source projects that have the resources to manage the influx of reports.
Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.