Zero Day Room
Live
Vulnerabilities

Anthropic's Claude Mythos finds 23,000 bugs

Anthropic's Claude Mythos Preview AI identified over 23,000 potential vulnerabilities in open-source projects, but external reviewers have examined fewer

Anthropic's Claude Mythos Preview AI identified over 23,000 potential vulnerabilities in open-source projects, but...

Anthropic's Claude Mythos Preview AI model scanned 281 open-source projects and generated 23,019 candidate vulnerabilities. According to figures compiled by software supply chain company Echo and current as of May 22, 2026, external security firms have reviewed only 1,900 of these findings. Project maintainers received 1,596 reports, acknowledged 1,451, and implemented 97 fixes, resulting in 88 published security advisories. The remaining 21,119 candidate vulnerabilities have not been reviewed by anyone outside Anthropic.

Anthropic attributes this gap to a shortage of human reviewers. The slice that was checked supports this claim: 1,726 of the 1,900 reviewed candidates, or 90.8%, were confirmed as real vulnerabilities. Echo attached a caveat, noting the reviewed subset was unlikely to be a random sample. The 90.8% accuracy rate may reflect the quality of the best candidates, not the entire pile. Anthropic has not published accuracy data for the other 21,000 findings.

Severity ratings frequently mismatched

Twenty-seven of the 88 published advisories have been assigned CVEs. Claude Mythos initially rated eight as Critical, 15 as High, and four as Medium, with none rated Low. Independent CVSS scoring and the affected maintainers produced a different distribution: one Critical, 16 High, eight Medium, and two Low. Only one of the model's eight Critical ratings held after review.

Two downgrades illustrate what the AI model could not assess. For Temporal Server, Mythos assigned a Critical rating, describing a scenario where an attacker could control workflows across namespaces. Temporal's maintainers scored the issue 2.3 (Low), because exploitation requires an attacker to already control a namespace holding a privileged internal credential, and the impact is limited to known workflows. For MinIO, Mythos said Critical, an external security firm said High, and MinIO's maintainers settled on Medium, noting the attack requires an existing cluster root JWT and permits read access only. Severity depends on deployment assumptions and privilege boundaries, details difficult to infer from source code alone.

Findings that arrive pre-rated serve as triage input for security teams. Across the 27 CVEs, 14 had a severity mismatch. Thirteen were overstated by the model, and one, a flaw in the jq command-line JSON tool, was understated. A work queue sorted by the model's own ratings would have prioritized issues that did not warrant top attention.

Exploit capability shows a generational leap

Anthropic built a benchmark using 50 previously discovered vulnerabilities in the SpiderMonkey JavaScript engine within Firefox 147. Each model was given five attempts per vulnerability, for 250 total trials. Claude Mythos Preview successfully turned a known crash into a working arbitrary code execution exploit in 181 trials, a 72.4% success rate. It achieved partial register control in 29 additional trials.

In contrast, Claude Opus 4.6 managed only two successful exploits, a rate below 1%. This represents an approximately 90-fold improvement between model generations. Three important conditions accompany this result: every trial started from a crash someone had already found, the test harness removed Firefox's browser sandbox and other defense-in-depth protections, and Anthropic designed and ran the evaluation, which has not been independently replicated.

Costs have shifted as well. Anthropic reported turning a known Linux kernel use-after-free vulnerability into a working root exploit for less than $2,000 in inference costs and under a day of runtime. This exploit chain included a second use-after-free flaw the model found in the kernel's traffic-control scheduler. Finding a vulnerability worth acting on still costs a few thousand dollars, with no guarantee the result will be a high- or critical-severity flaw.

The bottleneck shifts to human review

A July 2026 Echo survey of more than 80 senior US security leaders found 37% identified detecting more vulnerabilities than they can remediate as the biggest barrier to improving software supply chain security. Only 11% said more detection or scanning would be their next investment. Anthropic has manually confirmed additional vulnerabilities it has not reported to maintainers, because its own team and external partners lack the review capacity to handle them.

Related coverage

More from Vulnerabilities