Endorlabs Benchmarking Claude Fable 5 Reveals Harness Impact on Security Outcomes
Article Content
- •Cursor harness with Claude Fable 5 achieved 72.6% FuncPass and 29% SecPass.
- •Claude Code harness resulted in lower scores: 59.8% FuncPass and 19% SecPass.
- •The agent harness significantly influences security outcomes more than the model itself.
Endorlabs benchmarked the Claude Fable 5 AI model using two different harnesses, revealing significant differences in security outcomes. The Cursor harness achieved a 72.6% FuncPass and 29% SecPass, while the Claude Code harness resulted in a 59.8% FuncPass and 19% SecPass. The results indicate that the agent harness has a more substantial impact on security outcomes than the model itself. Despite the improvements, the security scores remain below 30%, indicating that many vulnerabilities are still left unaddressed. This benchmarking exercise involved 200 real-world vulnerability-fixing tasks in actual projects, highlighting the importance of the agent scaffolding in achieving better security results. The findings prompt further investigation into the relationship between model capabilities and harness effectiveness.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2017-12440 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…