securityaffairs.com 9 Oct 2026, 13:56 UTC

Anthropic Launches Free Scanner to Find Flaws in Open Source Code

Anthropic Launches Free Scanner to Find Flaws in Open Source Code

ANTHROPIC has launched OSS Scanner, a free vulnerability scanner for open-source code aimed at helping maintainers identify and fix flaws before attackers exploit them. The project grew from lessons learned while testing Claude against real-world targets during Project Glasswing. In testing, Anthropic’s latest models scanned some of the world’s most widely used open-source software and identified more than 29,000 candidate vulnerabilities, with humans manually reviewing and triaging around 6,000 of them.

Anthropic stresses that the tool is fully automated and shares findings promptly, even when not all reports have been verified. Each report includes reproduction steps, a clear explanation, and a suggested fix when available, plus identification of the code change that introduced the flaw. During experiments, the scanner was capable of combining several vulnerabilities to produce working exploits that allowed remote code execution without login, affecting real projects.

Maintainers can apply to participate via a GitHub pull request; enrollment is based on criteria similar to the OSS-Fuzz project, prioritising critical infrastructure. Anthropic conducted an internal validation, with expert testers reviewing 97 high- or critical-severity findings across 48 projects; 85 (88%) met the CVD bar, 11 were real but duplicates or other findings, and one was a false positive. The emphasis remains on speed and volume—faster scanning for faster patching—with the caveat that some reports will require further verification.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline