top of page

Anthropic says Claude has disclosed 6,157 vulnerabilities across 591 open-source projects

2 minutes ago
6 min read
Anthropic Claude disclosed 6,157 vulnerabilities across 591 open-source projects

Anthropic says Claude models have now helped disclose 6,157 security vulnerabilities across 591 open-source projects, providing one of the clearest public demonstrations so far of AI being used at industrial scale for vulnerability discovery.


The figures come from Anthropic's coordinated vulnerability disclosure program, which uses Claude models — including an early snapshot of Claude Mythos Preview — to analyze open-source software, generate vulnerability candidates and support reporting to affected maintainers.


As of October 2, Anthropic reports that 516 vulnerabilities have been patched upstream, while the program has produced 584 formal security identifiers: 219 CVEs and 365 GitHub Security Advisories.


The disclosure pipeline also includes independent security firms that review Claude-generated findings before reporting. Anthropic says 5,674 of 6,123 externally reviewed findings were confirmed valid, equivalent to a 92.7% true-positive rate for that reviewed subset.


··········


CLAUDE VULNERABILITY DISCLOSURE PROGRAM AT A GLANCE


........


Metric

October 2, 2026

Vulnerabilities disclosed

6,157

Open-source projects affected

591

Findings acknowledged by maintainers

5,103

Vulnerabilities patched upstream

516

CVE records issued

219

GitHub Security Advisories issued

365

Total CVE + GHSA identifiers

584

Findings reviewed by external security firms

6,123

Externally reviewed findings confirmed valid

5,674

True-positive rate in reviewed subset

92.7%


........


The headline number should not be interpreted as 6,157 vulnerabilities already published in full technical detail.


Anthropic uses coordinated vulnerability disclosure, meaning affected maintainers are generally notified privately before exploit details become public. The dashboard therefore distinguishes between findings already reported through the disclosure process and findings whose disclosure windows have closed and can be described publicly.


··········


CLAUDE FIRST GENERATES CANDIDATES AND HUMAN SECURITY TEAMS THEN FILTER THEM


The program operates as a multi-stage security pipeline rather than allowing a model to publish vulnerabilities autonomously.


Claude analyzes software and produces potential vulnerability findings. Those candidates can then move through human triage, technical validation and coordinated reporting before maintainers receive them.


Anthropic works with external security organizations including Ada Logics, Anvil, Calif.io, Doyensec, Ophion Security and Trail of Bits to evaluate findings and participate in disclosure.


The distinction between AI discovery and human validation is important because automated security analysis can generate plausible-looking findings that fail under closer examination.


For the 6,123 findings reviewed by external security firms, 5,674 were confirmed as valid, corresponding to Anthropic's reported 92.7% true-positive rate.


Some findings are also reported directly by Anthropic rather than moving through the same external-review path. The company explicitly notes that those findings can still contain false positives, so the 6,157 disclosure count should not be treated as equivalent to 6,157 independently confirmed vulnerabilities.


··········


THE DISCLOSURE COUNT HAS RISEN SHARPLY SINCE AUGUST


Anthropic's August 26 snapshot reported 2,300 disclosed vulnerabilities across 392 open-source projects.


By October 2, those figures had increased to 6,157 vulnerabilities across 591 projects.


........


Metric

August 26

October 2

Change

Vulnerabilities disclosed

2,300

6,157

+3,857

Open-source projects

392

591

+199

Patched vulnerabilities

421

516

+95

CVE + GHSA identifiers

462

584

+122


........


Data Studios calculation: between the August 26 and October 2 snapshots, the headline disclosure count increased by approximately 168%, while the number of affected projects increased by approximately 51%.


The number of patched vulnerabilities increased much more slowly, by approximately 23% over the same comparison.


That divergence illustrates the operational constraint created by high-volume automated discovery: finding vulnerabilities can scale faster than maintainers can investigate, prioritize, patch and release fixes.


··········


THE BOTTLENECK IS MOVING FROM DISCOVERY TO TRIAGE AND REMEDIATION


Anthropic reports that Claude has generated substantially more vulnerability candidates than ultimately appear in the headline disclosure number.


The limiting factor is increasingly the human process surrounding each finding: reproducing the issue, determining whether it is exploitable, establishing severity, contacting the appropriate maintainer and giving the project time to release a correction.


Anthropic describes independent human triage and review as the rate-limiting step in the program.


This creates a different scaling problem from conventional security research.


If an AI system can examine repositories continuously and generate candidate vulnerabilities much faster than human researchers, security organizations need additional capacity downstream: triage specialists, disclosure coordinators and maintainers capable of producing safe patches.


The capability of the model therefore becomes only one component of the system's total throughput.


··········


ONLY 516 OF THE DISCLOSED FINDINGS ARE CURRENTLY LISTED AS PATCHED UPSTREAM


Anthropic says 516 vulnerabilities have been patched upstream as of October 2.


That represents roughly 8.4% of the 6,157 headline disclosure count, although the ratio should not be interpreted as a conventional remediation rate.


Data Studios calculation: 516 divided by 6,157 equals approximately 8.38%.


Many disclosures are still inside active coordination windows, some were reported recently, and some maintainers may have acknowledged findings without yet releasing fixes.


A patch being released upstream also does not mean every affected downstream installation has already received or installed it. Package maintainers, operating-system distributions and end users can introduce additional delays between the upstream correction and effective remediation.


Anthropic separately reports 5,103 maintainer acknowledgements, indicating that a much larger share of the disclosed findings has reached the projects involved even when a patch has not yet been released.


··········


CLAUDE IS FINDING MEMORY-SAFETY, CRYPTOGRAPHIC AND CONTAINER SECURITY FLAWS


The public portion of Anthropic's disclosure ledger includes vulnerabilities spanning several security classes.


Examples include heap buffer overflows, stack buffer overflows, use-after-free errors, denial-of-service conditions, SQL injection, cryptographic signature bypasses and filesystem security problems.


Publicly revealed findings include issues affecting widely used projects such as Wireshark, wolfSSL, dnsmasq, ImageMagick, Asterisk, libexpat, runc and other open-source infrastructure.


Some findings affect low-level libraries or parsers where malformed inputs can trigger memory corruption. Others involve higher-level security boundaries, including authentication, container isolation or validation logic.


This breadth indicates that Claude is being applied beyond one narrow bug category or programming language.


The challenge for automated systems is not simply finding suspicious code patterns, but producing enough technical evidence for a human reviewer to reproduce the failure and determine whether it represents a genuine security vulnerability.


··········


CLAUDE'S SEVERITY RATINGS ARE CLOSE TO HUMAN REVIEW BUT NOT IDENTICAL


Anthropic also compares Claude's initial severity assessments with those assigned by external security firms.


Across a reviewed subset of 1,337 findings, the model and external reviewers produced the same severity category 83.0% of the time.


They were within one severity band in 97.1% of cases.


The remaining disagreement reflects a limitation of automated severity estimation. Determining whether a vulnerability is low, medium, high or critical often depends on project-specific context that is not visible from source code alone.


A vulnerability that appears technically severe can become less consequential if the vulnerable component is difficult to reach in a real deployment. Conversely, an apparently limited flaw can become more serious when it sits on a security-sensitive path.


Maintainers therefore remain an important source of contextual severity assessment even when the technical bug itself was discovered automatically.


··········


COORDINATED DISCLOSURE IS BECOMING PART OF THE AI SECURITY STACK


Anthropic's disclosure policy generally targets a 90-day disclosure window, with technical details potentially released earlier when a patch becomes available.


The process attempts to balance two competing requirements.


Maintainers need enough time to understand a vulnerability and prepare a correction before exploit information becomes broadly available. At the same time, vulnerabilities cannot remain private indefinitely once they have been identified and reported.


AI changes the scale of that coordination problem.


A human security research team might discover vulnerabilities at a rate that individual maintainers can absorb. A model capable of scanning many repositories in parallel can produce findings at a substantially higher rate, creating pressure on the disclosure infrastructure itself.


Anthropic's dashboard therefore tracks not only vulnerabilities but also acknowledgements, patches, advisory identifiers, external validation and disclosure status.


Those operational metrics become increasingly important as automated vulnerability discovery moves from isolated research demonstrations into persistent production systems.


··········


AI VULNERABILITY RESEARCH IS BEGINNING TO OPERATE AT SOFTWARE-ECOSYSTEM SCALE


Anthropic's October figures show a security system operating across hundreds of independent open-source projects rather than a small benchmark or curated vulnerability dataset.


Claude-generated findings are being reviewed by professional security firms, sent to maintainers, converted into CVEs and GitHub Security Advisories and, in hundreds of cases, followed by upstream patches.


The 6,157 disclosed findings across 591 projects also expose the next constraint in AI-assisted cybersecurity: discovering vulnerabilities faster does not automatically make software secure faster.


Validation, coordination, patch development and deployment remain human- and organization-intensive processes.


As models become better at finding software flaws, the competitive advantage may increasingly shift from raw discovery capability toward the ability to operate a complete AI-to-human security pipeline that can validate findings, prioritize risk and move fixes into production without overwhelming maintainers.


··········


FOLLOW US FOR MORE.


DATA STUDIOS


datastudios.org

bottom of page