All findings

CVE-2026-27654 + 17 more critical

Anthropic CVD dashboard reveals fixed Mythos Preview open-source findings

Anthropic's Project Glasswing CVD dashboard revealed 27 fixed, CVE/GHSA-backed open-source entries attributed to Claude Mythos Preview, including NGINX, wolfSSL, Nomad, Temporal, Mastodon, FreeRDP, jq, MapServer, Gitoxide, Ghost, Craft CMS, and other projects.

Bug class
Project Glasswing CVD cluster: path traversal, broken access control, SSRF, heap overflow, SQL injection, RCE, and privilege escalation
Affected codebase
Multiple open-source projects
Credited system
Claude Mythos Preview
Disclosed
May 20, 2026
Attribution
Direct source attribution
Severity
critical
Source status: Anthropic's May 2026 Project Glasswing CVD dashboard and ledger directly mark these entries as discovered by Claude Mythos Preview, passed triage, vendor-confirmed, disclosed, patched, and fixed. The cveId field tracks 18 unique CVE IDs across 19 CVE-backed rows; GHSA-only fixed records are covered in the body.

Summary

Anthropic’s coordinated vulnerability disclosure dashboard is a new public source for Project Glasswing findings. The May 22 snapshot says Anthropic had disclosed 1,596 vulnerabilities across 281 open-source projects, with 97 patched and 88 assigned a CVE or GitHub Security Advisory.

Bugflation does not count those headline numbers as individual findings. This entry indexes the subset that is publicly revealed, fixed, vendor-confirmed, and backed by CVE or GHSA identifiers in Anthropic’s ledger.

The revealed fixed cluster now includes 27 entries across NGINX, wolfSSL, Mastodon, FreeRDP, MinIO, Nomad, jq, libyang, MapServer, Gitoxide, Temporal, junrar, Ghost, Craft CMS, and ImageMagick. Nineteen of those rows have CVE IDs, with 18 unique CVEs because the two NGINX rows share CVE-2026-27654:

The GHSA-only side of the cluster includes Craft CMS, one additional FreeRDP row, Gitoxide, ImageMagick, junrar, libyang, MinIO, and Ghost.

Some NGINX and wolfSSL CVEs in this CVD ledger also carry public Calif.io, Claude, and Anthropic Research credit lines. Bugflation keeps that broader Claude-assisted MADBugs entry separate; this page is scoped to the Anthropic CVD ledger’s direct Claude Mythos Preview attribution and fixed-row status.

Attribution

This is a direct-attribution entry. The per-finding Anthropic pages state that the vulnerabilities were discovered by Claude Mythos Preview. The ledger marks the entries as passed triage, vendor-confirmed, disclosed, patched, and fixed.

The dashboard also exposes a machine-readable ledger, which makes the count auditable without relying on screenshots or secondary reporting. The CVE and GHSA records provide the public vulnerability layer; Anthropic supplies the AI attribution and disclosure-status layer.

Why it matters

This is the first public Project Glasswing source that moves beyond isolated examples and exposes an auditable CVD pipeline. The important signal is not the raw number of undisclosed candidates. It is the much narrower, verifiable path from Mythos-generated report to human triage, maintainer confirmation, fix, and public advisory.

The cluster also shows the practical shape of bugflation: the bottleneck is not just model discovery. It is independent triage, vendor coordination, advisory assignment, patch validation, and public disclosure.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.