Eigen RadarAI
Analysis

Anthropic’s disclosure tally separates Claude findings from shipped fixes

Anthropic’s October 2 security dashboard reports 6,157 vulnerability disclosures across 591 open-source projects, with 516 upstream patches known to the company. Claude models generate candidate findings, while outside specialists and software maintainers handle later stages. The snapshot makes the gap between finding a potential flaw, notifying its developers and shipping a fix visible within one coordinated disclosure program.

Artificial Intelligence··Midday
Two software maintainers examine code changes together in a bright workspace.

Disclosures and patches have different totals

Anthropic, the company developing Claude AI models, published an October 2 update to its coordinated vulnerability disclosure dashboard. It tracks potential security weaknesses in open-source software and their passage toward maintainer notification. The company reports 6,157 disclosures across 591 projects, with 516 upstream patches known to it. These are figures for its own program, covering work by several Claude models, including an early Claude Mythos Preview snapshot.[1], [2]

Human review separates candidates from confirmed bugs

External security specialists reproduce candidate findings, assess their severity and prepare reports for maintainers. Anthropic’s snapshot separates that reviewed route from findings it sends directly. Some maintainers request untriaged findings, and direct reports can include false positives. A confirmed bug may also have been reported already or fall outside a project’s threat model, affecting whether its maintainers decide to fix it.[1]

The ledger preserves commitments through disclosure

The disclosure ledger commits findings through cryptographic hashes before public technical details appear. Status and severity assessments are added after notification; project names and bug classes are revealed when the disclosure window closes. Withdrawn commitments keep their hashes. Human triage and review capacity limits how quickly model findings become completed disclosures. An upstream patch count also differs from deployment: shipping a fix does not establish that users have installed it.[1]

References

  1. News sourceAnthropic Frontier Red TeamAnthropic publishes an updated accounting of Claude vulnerability disclosures↩1↩2↩3
  2. News sourceVM Tech SolutionsAnthropic updates its Claude vulnerability disclosure dashboard↩