{
  "id": 13720093,
  "title": "Claude found 29,000 possible bugs in open source. Only 516 have been fixed.",
  "url": "https://urgent.news/2026/10/11/claude-found-29-000-possible-bugs-in-open-source-only-516-have-been",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-11T13:00:00.000Z",
  "source": {
    "name": "The New Stack",
    "slug": "the-new-stack",
    "url": "https://thenewstack.io/anthropic-oss-scanner-vulnerabilities/"
  },
  "original_language": "en",
  "account": "Anthropic, the developer of the AI chatbot Claude, has launched an open-source scanning tool called OSS Scanner as part of its Cyber Mission. The tool has identified over 29,000 potential vulnerabilities in widely used open-source projects, but only 516 have been fixed. The majority of these findings have yet to be reviewed, with only 6,123 out of the 29,000 reviewed by external security research firms, of which 516 were confirmed as valid. Anthropic is offering a fast-track option, providing the findings to eligible projects without verification, leading to rapid disclosure. However, this bypasses the current backlog of vulnerabilities. Experts have noted that while the scanner's output is promising, it has also raised concerns about inflated severity ratings and misinterpretation of a project's threat model. Some maintainers have reported that Anthropic's reports are of high quality, providing necessary context and even proposed fixes. The company has restricted access to established open-source projects that have the resources to manage the influx of reports.",
  "summary": "Anthropic’s new OSS Scanner, launched last week as part of its broader Cyber Mission, exposes a problem inside the company’s The post Claude found 29,000 possible bugs in open source. Only 516 have been fixed. appeared first on The New Stack .",
  "key_points": [
    "Anthropic's OSS Scanner found 29,000 possible bugs in open source projects.",
    "Only 516 vulnerabilities have been fixed out of the identified 29,000.",
    "Anthropic offers fast-track disclosure to eligible projects without verification."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}