Claude Found 29,000 Possible Bugs — Only 516 Got Fixed

Anthropic's OSS Scanner surfaced nearly 30,000 candidate vulnerabilities in open source, yet its dashboard shows just 516 upstream fixes so far.

7 pages3 sources3 min read

Claude Found 29,000 Possible Bugs — Only 516 Got Fixed

By @sharedot · · 8 pages

  • Programming
  • Open Source
  • Cybersecurity
  • AI Tools

Anthropic's OSS Scanner surfaced nearly 30,000 candidate vulnerabilities in open source, yet its dashboard shows just 516 upstream fixes so far.

The Gap Between Finding and Fixing

Anthropic's vulnerability disclosure dashboard, captured in an October 2 snapshot, listed 29,439 candidate findings from its AI scanning of open-source software. Of those, 6,123 had been reviewed by external security firms, 5,674 were classified as valid, and 6,157 reports had gone to maintainers across 591 projects. The number that matters most to users: only 516 upstream fixes are known to the company. The New Stack distilled the situation bluntly in its headline — Claude found 29,000 possible bugs in open source, and only 516 have been fixed.

Why It's Surprising: Humans Are the Bottleneck

The surprise is not that AI can find bugs — it is how slowly the rest of the pipeline converts findings into shipped patches. Anthropic launched OSS Scanner as a free service that runs periodic scans using its most capable models and delivers reports to maintainers with no human triage before they arrive, as LinkedIn's analysis notes. That means participating projects must themselves decide whether each reported issue is real, warrants a fix, and isn't a duplicate — the exact assessment work that used to happen before a report ever landed in an inbox.

The Evidence So Far

According to LinkedIn's writeup of Anthropic's launch announcement, external penetration testers examined 97 high- and critical-severity findings from an early scanner version across 48 projects: 85 met the company's coordinated disclosure standards, eleven were real but duplicated known issues or other scanner findings, and one was invalid. The New Stack reports that Anthropic acknowledged feedback about exaggerated severity ratings and misunderstandings of project threat models, while maintainer testimonials from PostgreSQL, OpenSSL, wolfSSL, HotCRP and curl were included in the announcement.

What Maintainers Sign Up For

Per egamers.io, Anthropic says it expects reports to be more than 90 percent accurate but admits they may contain errors — and no one at the company checks them first. Enrollment happens through the official GitHub repository via a pull request with project configuration, a contact address and build instructions; an optional threat-model file can spell out security assumptions and out-of-scope areas. Scans run in isolated virtual machines with internet access removed, and findings arrive by email with reproduction details and proposed patches where available. The outlet's advice for maintainers is to treat every report like a pull request from a stranger and reproduce each flaw before merging any suggested patch.

The Stakes for the Software Supply Chain

Almost all modern software is built on open-source code that small volunteer teams maintain without a security department, and those are precisely the teams that must absorb the review burden if roughly one in ten automated reports is wrong. The history is cautionary: LinkedIn notes that curl founder Daniel Stenberg described in July 2025 how low-quality, AI-generated submissions consumed his team's limited time, with only about 5% of submissions proving genuine. Earlier discovery only reduces exposure if findings become reviewed patches, supported releases and deployed updates — and the 516-fix figure suggests that leap is where the system strains.

What Comes Next

The 516 figure is a lagging indicator, and an upstream fix does not guarantee downstream users have installed it. Anthropic's documentation distinguishes automated, unvalidated scanner reports — which initially carry no standard 90-day disclosure period — from findings it validates through its coordinated vulnerability disclosure process, where a 90-day clock starts after the project is notified. OSS Scanner also sits inside a wider push: LinkedIn and egamers.io both connect it to Anthropic's Cyber Mission and its Critical Infrastructure Defense Program for power grids, water systems and transportation networks. The real test, as both analyses argue, will be measured in confirmed findings fixed and updates actually reaching users.

Sources

  1. thenewstack.io › Claude found 29,000 possible bugs in open source. Only 516 have been fixed.
  2. linkedin.com › Anthropic Launches Free AI Security Scanner To Help Open-Source Projects Find and Fix Vulnerabilities
  3. egamers.io › Anthropic Launches Free AI Vulnerability Scanner For Open-source Maintainers, With No Human Review

More on Programming