Resources · Vulnerability Disclosures
Anthropic's Coordinated Vulnerability Disclosure Dashboard
A structured view of the vulnerability disclosure data that Anthropic publishes for its Coordinated Vulnerability Disclosure (CVD) programme, in which Claude models find vulnerabilities in open-source software and the findings are reported to project maintainers. Every figure, record and ledger entry on this page comes from Anthropic's public CVD dashboard, ledger and methodology pages.
Independent presentation by IntelliXBOM of data published by Anthropic. IntelliXBOM is not affiliated with Anthropic and this page is not endorsed by Anthropic. Anthropic's own pages are the authoritative source; see Source & attribution. Retrieved October 7, 2026.
01 · Overview
What this dashboard tracks
Anthropic uses Claude models, including an early snapshot of Claude Mythos Preview, to find security vulnerabilities in open-source software. We partner with external security research firms to triage findings, validate them, and report human-reviewed vulnerabilities, prioritizing critical- and high-severity ones, to the software's maintainers under our Coordinated Vulnerability Disclosure policy (opens Anthropic site in a new tab). This page tracks the findings that we've disclosed, and, in line with our policy, publishes details of the ones whose disclosure window has now closed.
As of October 2, 2026, we've disclosed 6,157 vulnerabilities across 591 open source projects. To our knowledge, 516 of these have been patched. Across all findings in the ledger, 584 identifiers have been issued: 219 CVE records and 365 GitHub Security Advisories (a single finding may carry both). In other cases, maintainers have shipped a fix without publishing an advisory. The number of vulnerabilities we've disclosed is a subset of the total number of vulnerabilities that Mythos Preview (and other Claude models) has found, since the process of independent human triage and review is the rate limiting step.
This page covers a headline count of the vulnerabilities we've disclosed. For those vulnerabilities we've disclosed and where the disclosure window has now closed, it also includes identifier records (CVE & GHSA) and finding details, further below.
Finally, it includes a disclosure ledger. The ledger lists hash commitments for findings we have reported or plan to report. The details we publish later can be checked against them.
Anthropic, Coordinated vulnerability disclosure dashboard (opens Anthropic site in a new tab)
02 · Key statistics
Headline figures
All findings, as of October 2, 2026. These are the unfiltered headline figures. Use the pipeline filters below to narrow them by severity, assessment source and discovery date.
03 · Disclosure pipeline
From candidate to advisory Filters active
Anthropic's flowchart of the disclosure process, filterable by severity, assessment source and discovery date. With JavaScript turned off, the default figures are shown.
Page filters (apply to the pipeline, identifier records and ledger; the date range also applies to the severity heatmap)
Showing all assessment sources and severities for findings discovered between November 1, 2025 and October 2, 2026.
Counts as of October 2, 2026
How these figures are produced
The statistics above reflect all bugs found by Claude Mythos Preview and other Claude models. They can also be filtered by severity under at least one of three assessment sources: Claude's own assessment, the assessment of the external security research firm that triaged the finding, or the project maintainer's assessment. Each source is defined in the glossary on the About page, and the filtered view states how many findings the selected sources have not assessed. These figures are designed to reflect our coordinated vulnerability disclosure process, which works approximately as follows. A glossary of the terms is available on the About page.
First, our models find candidate vulnerabilities, which we add to a list for human triage. This is the figure at the top. The count includes candidates from Mythos Preview, other Mythos-class models and other Claude models.
Then, in order to disclose a vulnerability to a maintainer, we take one of two steps.
Triage: We pass them to one of six external security research firms that we have engaged for this endeavor. The security research firms reproduce each issue, assess whether it is a real bug (and if so, assess how severe it is), and then write a report for confirmed bugs that will go to the project's maintainer. Importantly, there are many additional bugs that we or our security partners have investigated and confirmed are real but that we have not yet reported to maintainers, due to capacity limitations.
In our triage process, the "true positive rate" (the number of findings confirmed as valid, as a share of the number of findings manually reviewed) reflects how often the external security research firms determined that a finding Mythos Preview (and other Claude models) produced was a real vulnerability. This includes real bugs that we later discover have already been reported, and "won't fix" findings (the bug is real, but the maintainer is unlikely to address it, e.g. because it falls outside the project's threat model, or affects code that isn't typically reachable). We include these in the true positive rate because we're reliant on our security research partners (rather than maintainers) to tell us how many bugs they've confirmed, and it's only after the maintainers have received the report and assessed the vulnerability that we'll learn whether a vulnerability is one they plan to fix. For this reason, it's also possible that a vendor has marked a vulnerability as a true positive (or a false positive) in error. Given this, the number of "true positives" in the dashboard above should only be taken as one proxy for impact. Another, more reliable one is the number of patches created, though this is only a lagging indicator of progress, since patches take a long time to create.
Direct disclosure: Other vulnerabilities are disclosed to maintainers directly, without the same independent check. This also happens when maintainers specifically request that we provide them un-triaged findings.
Once bugs have either been triaged or directly disclosed, "Acknowledged by maintainer" counts all bugs whose reports maintainers have responded to. "Patched upstream" counts the reported vulnerabilities that maintainers have since created and released fixes for, whether or not they replied to the report, though this does not guarantee that those patches have been widely installed. Finally, "CVEs and GHSAs assigned" counts the CVE records and GitHub Security Advisories issued across all findings in the ledger, whether or not a patch has shipped (a finding may carry both). Some advisories are now public, and we list them out further down on this page. We leave whether to create a security advisory up to the discretion of maintainers.
See About for more information.
Anthropic, Coordinated vulnerability disclosure dashboard (opens Anthropic site in a new tab). The glossary and the About page are reproduced below in About & methodology.
04 · Severity agreement
Claude's severity vs external review Filters active
Claude vs external security research firm
Shown on Anthropic's dashboardView as table
| Claude ↓ / Firm-assessed → | critical | high | medium | low |
|---|---|---|---|---|
| critical | 116 | 121 | 7 | 15 |
| high | 14 | 828 | 23 | 12 |
| medium | 2 | 25 | 148 | 2 |
| low | 3 | 0 | 3 | 18 |
This graph compares Claude's initial severity assessments against the external security research firms' assessments, for those findings that have completed triage. Cells on the diagonal indicate agreement. The number assessed here represents the subset of vulnerabilities included on our disclosure ledger that were reviewed by our security partners, rather than disclosed by us directly.
Anthropic's severity assessments are produced before any maintainer input. Project maintainers often apply project-specific severity rules that Claude does not have access to at run time, so what one maintainer rates as critical another may rate as low. The external security research firms incorporate that context, which is why their assessments tend to be lower.
Anthropic, CVD dashboard (opens Anthropic site in a new tab)
Claude vs project maintainer
From payload.json · not charted on the source pageView as table
| Claude ↓ / Maintainer-assessed → | critical | high | medium | low |
|---|---|---|---|---|
| critical | 3 | 10 | 9 | 1 |
| high | 9 | 64 | 45 | 9 |
| medium | 0 | 1 | 6 | 2 |
| low | 0 | 0 | 2 | 2 |
05 · Ledger insights
What the ledger contains
Breakdowns that IntelliXBOM calculated from Anthropic's published data files (revision 35). Anthropic does not publish these as separate figures. Each count comes straight from a field in the files, with no estimates and no weighting. These charts cover the whole ledger and are not affected by the page filters.
Ledger entries by disclosure stage
payload.json · tier_partitionreveal_tier. The stage controls which fields the ledger publishes. A revealed entry shows its identifier, project and bug class. A sent or acknowledged entry shows its status and severity. A committed entry shows only its hash and commitment date.Severity ratings published in the ledger
ledger.json · *_severityView as table
| Source | critical | high | medium | low | Not published / not assessed |
|---|---|---|---|---|---|
| Claude-assessed | 315 | 1,285 | 2,381 | 2,171 | 445 |
| Firm-assessed | 137 | 976 | 181 | 47 | 5,256 |
| Maintainer-assessed | 13 | 76 | 63 | 14 | 6,431 |
Ledger entries by month committed
ledger.json · committed_at- 7Feb '26
- 82Mar '26
- 252Apr '26
- 1,388May '26
- 12Jun '26
- 462Jul '26
- 3,812Aug '26
- 308Sep '26
- 274Oct '26
View as table
| Month | Entries |
|---|---|
| Feb 2026 | 7 |
| Mar 2026 | 82 |
| Apr 2026 | 252 |
| May 2026 | 1,388 |
| Jun 2026 | 12 |
| Jul 2026 | 462 |
| Aug 2026 | 3,812 |
| Sep 2026 | 308 |
| Oct 2026 | 274 |
Ledger entries by month discovered
ledger.json · discovered_on- 2Nov '25
- 5Dec '25
- 2Jan '26
- 12Feb '26
- 509Mar '26
- 1,745Apr '26
- 2,424May '26
- 1,021Jun '26
- 163Jul '26
- 155Aug '26
- 121Sep '26
View as table
| Month | Entries |
|---|---|
| Nov 2025 | 2 |
| Dec 2025 | 5 |
| Jan 2026 | 2 |
| Feb 2026 | 12 |
| Mar 2026 | 509 |
| Apr 2026 | 1,745 |
| May 2026 | 2,424 |
| Jun 2026 | 1,021 |
| Jul 2026 | 163 |
| Aug 2026 | 155 |
| Sep 2026 | 121 |
Revealed findings by status
ledger.json · reveal_tier = revealedWithdrawal and merge reasons
ledger.json · withdrawn_reasonRevealed findings by bug class
ledger.json · bug_classRevealed findings by project
ledger.json · projectAll 113 projects
06 · Vulnerability records
Published CVE and GHSA records Filters active
94 CVE and 63 GHSA records that the assigning authority has published, for findings whose disclosure window has closed. Each record shows the project, bug class, severity, Anthropic finding identifier (linking to Anthropic's finding card) and title. Advisory links go to NVD or GitHub. Of the 584 identifiers issued in total, 332 are counted as published in Anthropic's payload (advisories_published).
CVEs 94
payload.json · cve_recordsCommon Vulnerabilities and Exposures records assigned to findings disclosed through this program. The records below are publicly available. Identifiers not listed belong to findings whose disclosure window has not yet closed, or have not yet been published by the assigning authority.
No published records match the current filters.
GHSAs 63
payload.json · ghsa_recordsGitHub Security Advisory records assigned to findings disclosed through this program. The records below are publicly available. Identifiers not listed belong to findings whose disclosure window has not yet closed, or have not yet been published by the assigning authority.
No published records match the current filters.
07 · Disclosure ledger
Vulnerability disclosure ledger Filters active
Each entry is a SHA-3-512 hash of one finding's details. "Date committed" comes from our records. It can be earlier than the date the hash was computed or first listed here. Each ledger entry shows more detail as it progresses through disclosure: before the maintainer has been notified, only the commitment hash and the commitment date are published; once the report has been sent, the status and the severity assessments are shown and the discovery date is published (it drives the date filter); and the identifier, project, and bug class are revealed only when the disclosure window closes. A commitment that is withdrawn at any stage keeps its hash and commitment date and is marked withdrawn in the status column; a commitment withdrawn before the finding was revealed is also struck through in the table.
Anthropic, Disclosure ledger (opens Anthropic site in a new tab)
The "disclosed" tile counts every entry whose report has been sent, so it includes fixed entries and entries withdrawn after reveal. This matches how Anthropic's ledger counts it.
Local filters are overriding the page filters for this table.
| Severity assessments | |||||
|---|---|---|---|---|---|
| 2026-10-02 | 425c35d5b403485da0bd… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 6e35454ade4c90f28cc5… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | ac8c9b7be18e2994f42d… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | d374165be765d159432f… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 0aa4a1d9f1155fabb3f4… | Withheld | Withheld | Claude: low | disclosed |
| 2026-10-02 | 5b928ab1e814957714b3… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 60b187740e40f297e179… | Withheld | Withheld | Claude: critical | disclosed |
| 2026-10-02 | 10864ef6de77876f6a1f… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 442eb7982813893880c3… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 7fd14ea02d40cef3f435… | Withheld | Withheld | Claude: high | disclosed |
| 2026-10-02 | 5b38fdefae40ed1d7857… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 8f10479a05c41bca1d34… | Withheld | Withheld | Claude: high | disclosed |
| 2026-10-02 | 999c9f7f359013a42ce9… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 8f8d854b428a7947f099… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | ded647e8e0587edcd44e… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | dcaeabfd36e7af88c7fd… | Withheld | Withheld | Claude: high | disclosed |
| 2026-10-02 | 100519bc750acaac63ea… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 470c01c005ff35436475… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 47da586fc4488c1d384f… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | af0b7587b917aee5faea… | Withheld | Withheld | Claude: highFirm: low | disclosed |
| 2026-10-02 | 840d38765b32fb734179… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | a223d1b847987d769510… | Withheld | Withheld | Claude: high | disclosed |
| 2026-10-02 | 0b4c98d39abb85e38342… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 31db2aa4e6a3aefc755a… | Withheld | Withheld | Claude: medium | disclosed |
| 2026-10-02 | 1902f80229aac596df22… | Withheld | Withheld | Claude: medium | disclosed |
Select a row to expand it and see every field Anthropic publishes for the entry: full hash, discovery, reveal and patch dates, CVE and GHSA identifiers, corrections, withdrawal reason and date, merge target and triage flags. Fields Anthropic has not yet published are marked as withheld. Full data: ledger.json (opens Anthropic site in a new tab) · payload.json (opens Anthropic site in a new tab).
08 · About & methodology
About Anthropic's CVD programme and this data
Reproduced from Anthropic's About this dashboard (opens Anthropic site in a new tab) page, with the provenance notes from the dashboard and ledger.
About this dashboard
Anthropic uses Claude to discover security vulnerabilities in widely used open-source software. When a finding is validated, the affected project's maintainers are notified privately and given time to issue a fix before details are made public consistent with the timelines provided in our Coordinated Vulnerability Disclosure (opens Anthropic site in a new tab) policy. This site summarizes the program's progress as of October 2, 2026.
External security research firm partners
The following are the external security research firms that work with us to triage Claude's vulnerability findings and notify project maintainers.
Glossary
| Term | Definition |
|---|---|
| Candidates | Every distinct crash or vulnerability hypothesis that Claude produced across the program, before any triage. |
| True positive rate | The share of firm-reviewed findings confirmed as real, including duplicates and "won't fix" findings. |
| Total reported to maintainers | A finding whose report has been sent to the project maintainer. |
| Acknowledged by maintainer | The maintainer has responded to the report. The count of these findings reflects the fact the OSS maintainers are experiencing a higher volume of inbound security findings. Our teams reach out to maintainers based on the severity of the findings and existing maintainer volume. |
| Patched upstream | A patch has landed after the report was sent. |
| CVEs and GHSAs assigned | A CVE or GHSA identifier assigned to a finding. Identifiers themselves are listed once the finding's disclosure window has closed and the assigning authority has published the record. |
| Disclosure window | See Anthropic's Coordinated Vulnerability Disclosure policy (opens Anthropic site in a new tab). |
| Commitment hash | A SHA-3-512 hash of the finding's details, which we call the preimage. |
| Ledger | The record of commitment hashes and their reveal state. Hashes are never removed, and once a finding has been revealed, its identifier, project, bug class, advisories, severities and dates are never removed; a finding may later be marked withdrawn or merged, with the date and, where recorded, the reason. An advisory identifier published in error stays visible as a struck-through correction rather than being removed. A patch date published in error stays on the finding's timeline, worded as a correction, and moves from patched_at to corrected_patched_at in ledger.json. A finding withdrawn while it remains revealed keeps its full card; only when a finding's reveal is cleared after publication are its report text and preimage withheld. |
| Withdrawn | A commitment that is no longer active. For example, the finding was retracted or duplicated a known issue, or an edit to its details gave it a new hash and entry. Before the finding is revealed it shows only the hash and commitment date; after it has been revealed it keeps its identifier and advisories and is marked withdrawn with the date and reason. |
| Merged | A commitment whose finding was consolidated into another finding; the entry keeps its identifier and links to the surviving finding. |
| Severity | The assessor's rating of impact (critical, high, medium, low). |
| Claude-assessed severity | The severity Claude assigned when it first analyzed the finding, recorded on the canonical report before any external review. |
| Firm-assessed severity | The severity assigned by an external security research firm during triage. It exists only for findings a firm has reviewed. |
| Maintainer-assessed severity | The severity assigned by the project maintainer, typically through a published security advisory. It exists only when the maintainer has provided one. |
| Bug class | The vulnerability category. |
Verifying a commitment
The commitment hash is the SHA-3-512 digest of a canonical JSON document. The document has sorted keys, no whitespace between tokens, and is encoded as UTF-8. It contains the finding identifier, project, creation time, title, bug class, target commit, location, discovery time, Claude's and the security research firm's severity assessments, the description, technical details, reproduction steps, and the SHA-256 of the proof-of-concept artifact. Fields not known when the hash was computed are recorded as null. The preimage records each assessment as of the time the hash was computed; if the external security research firm later revises its severity, the card shows the current value marked as revised alongside the sealed one. To verify, download the preimage JSON from the finding card and confirm that its SHA-3-512 digest matches the commitment hash published on the ledger.
Each ledger entry shows more detail as it progresses through disclosure: before the maintainer has been notified, only the commitment hash and the commitment date are published; once the report has been sent, the status and the severity assessments are shown and the discovery date is published (it drives the date filter); and the identifier, project, and bug class are revealed only when the disclosure window closes. A commitment that is withdrawn at any stage keeps its hash and commitment date and is marked withdrawn in the status column; a commitment withdrawn before the finding was revealed is also struck through in the table.
Finding cards
Once a finding's disclosure window closes, its identifier in the ledger links to a finding card. A card shows the project, bug class, and severity. When the report body carries substantive content, the card also shows Anthropic's analysis of the finding. Every card links to any assigned advisory that the assigning authority has published, and shows the commitment hash. A card for a finding that remains published also shows the preimage JSON, so that the published card can be verified against the ledger entry that committed to it. A finding withdrawn while it remains revealed keeps its full card, report text and preimage included, marked as withdrawn after publication. Only a finding whose reveal was cleared after publication has its card replaced by a page that keeps the hash and identifiers but withholds the report text and the preimage, because the preimage is the withdrawn report.
On this page, every Anthropic finding identifier (ANT-…) links to its finding card on red.anthropic.com.
Changes between updates
The August 26, 2026 update showed dates in Pacific Time. They are now in UTC, so some are one day later.
Up to the August 26, 2026 update, finding cards listed "Reported to tracker". They now list "Discovered or logged" instead, and its date can be earlier.
Provenance
This snapshot was generated on 2026-10-02 19:47 UTC. The manifest hash below is the SHA-3-512 hash of the structured payload and is republished with every dated snapshot so any figure on this page can be verified against the machine-readable record.
- Revision
- 35
- Checksum (manifest SHA-3-512)
- 1fca6b3bafbdab0c2a55896e88c547016e90b28c554dc0b051895fc5639b0e5160b07598ccb6d2dcbfb9277b09a99ea81b4a4ba49cf36796a76fa7b6d97888f9
- Snapshot generated
- 2026-10-02 19:47 UTC
- Dates and times
- UTC
- Published by
- Anthropic Frontier Red Team
From Anthropic's page footer: "Dates and times are in UTC" and "Archived snapshots remain available at their dated paths so any figure can be verified against the page that was live on that date." See the archive (opens Anthropic site in a new tab).
Severity definitions used by the filters
- Claude-assessed
- The severity Claude assigned when it first analyzed the finding, recorded on the canonical report before any external review.
- Firm-assessed
- The severity assigned by an external security research firm during triage. It exists only for findings a firm has reviewed.
- Maintainer-assessed
- The severity assigned by the project maintainer, typically through a published security advisory. It exists only when the maintainer has provided one.
The page filters work the same way as Anthropic's. A finding is counted when it was discovered inside the selected date range and at least one selected source rates it at one of the selected levels. Each finding is counted only once. When you narrow the sources, a line under the filters reports how many reported findings the selected sources have not assessed.
09 · Source
Source & attribution
Data presented on this page is sourced from Anthropic's publicly available Coordinated Vulnerability Disclosure resources. The figures, records, ledger entries, dates, severities and statuses come from Anthropic's snapshot revision 35, last updated 2026-10-02 19:47 UTC, which IntelliXBOM retrieved on October 7, 2026. Explanatory text marked as quoted is Anthropic's own wording. IntelliXBOM rearranged the information and added the derived breakdowns in Ledger insights, each labelled with its source field. IntelliXBOM has not changed any value, date, classification or severity.
Anthropic updates its dashboard periodically. If a figure here differs from Anthropic's live page, Anthropic's page takes precedence. IntelliXBOM is not affiliated with Anthropic. The names "Anthropic" and "Claude" are used only to identify the source of the data.
- Anthropic CVD Dashboardred.anthropic.com/2026/cvd/ (opens Anthropic site in a new tab)
- Disclosure Ledgerred.anthropic.com/2026/cvd/ledger/ (opens Anthropic site in a new tab)
- About & Methodologyred.anthropic.com/2026/cvd/about/ (opens Anthropic site in a new tab)
- payload.jsonStructured payload (machine-readable) (opens Anthropic site in a new tab)
- ledger.jsonFull ledger (machine-readable) (opens Anthropic site in a new tab)
- Coordinated Vulnerability Disclosure policyanthropic.com (opens Anthropic site in a new tab)