Technology

Anthropic Launches Free Vulnerability Scanner for Open Source Software

10/9/2026, 05:02 PM • Evgenia Sliv

(edited: 10/09/2026)

Anthropic Launches Free Vulnerability Scanner for Open Source Software

Anthropic has launched a free service for finding vulnerabilities in open-source software, called OSS Scanner. It is intended for projects that voluntarily wish to participate in the program and receive periodic reviews using the company's powerful models, particularly Claude Mythos. The service is based on experience gained from the Project Glasswing initiative. Unlike the commercial product Claude Security, OSS Scanner focuses on helping open-source developers and offers free audits. Over the past six months, Anthropic has used its new models to review significant software projects. During these reviews, more than 29,000 potential vulnerabilities were identified, of which specialists were able to manually verify and prioritize only about 6,000.

Open-source developers are increasingly requesting that all identified issues be forwarded to them, even if they have not yet been verified. At the launch of OSS Scanner, Anthropic sent maintainers nearly 5,000 such reports with suggestions for fixes. The scanner will generate reports automatically, allowing for faster project scanning; however, Anthropic warns that the results may contain false positives, duplicates, or incorrect severity assessments. Before the launch, OSS Scanner was tested on dozens of open-source projects, resulting in several hundred bug reports. Upon further review of 97 critical and high-risk findings in 48 projects, 85 (88%) met quality standards. Eleven findings were real errors duplicating already known issues, and one was a false positive.

Some maintainers pointed out the possibility of overestimating the severity of issues or misinterpreting the threat model of a specific project. Anthropic will continue to improve the system based on developer feedback. Reports will include code to reproduce the vulnerability, an explanation of the issue, information on when it might have appeared in the code, and recommendations for fixes. Project maintainers who wish to join OSS Scanner can apply by creating a request in the service's GitHub repository, following the standard template and instructions. Anthropic will select projects based on the same criteria as OSS-Fuzz, with a focus on significant impact on infrastructure and user security.

This material is prepared solely for informational purposes and does not constitute financial advice or a recommendation.

Popular news