Z.ai ships GLM-5.3, model found 1,097 bugs
Archive item — written before sources were shown.
GLM-5.3 keeps GLM-5.2's weights, gaining capability purely from post-training, including an unplanned skill that found 2,436 real vulnerabilities in open code.
Z.ai released GLM-5.3 on August 14, an update to its open-weight GLM line that keeps the exact same base model as GLM-5.2 and gets every capability gain from scaled-up post-training alone, with no retraining of the underlying architecture. The company says its internal Code Bench coding score jumped 50% over GLM-5.2, and Terminal-Bench 3.0 rose from 4.6 to 28.3.
The bigger story is what the extra post-training compute produced on its own: a cybersecurity capability Z.ai says it did not train for. Turned loose on open-source repositories, the model formed complete multi-step exploit chains rather than flagging isolated bugs, surfacing 2,436 vulnerabilities across 269 projects, 1,097 of them rated critical or high severity. Z.ai has disclosed 53 with CVEs so far and put the rest under embargo while maintainers patch.
GLM-5.3 is live now through Z.ai’s API and GLM Coding Plan for existing subscribers; open weights follow in about two weeks after further safety hardening. On coding benchmarks it beats Claude Opus 4.8 while using fewer tokens, though it still trails Claude Fable 5 and GPT-5.6 Sol on some tasks.
What it means for you
A mid-tier coding model stumbled into exploit-chain reasoning as a side effect of ordinary post-training scaling. Nobody at Z.ai set out to build a hacking tool, and that’s worth sitting with. If you maintain open-source code, run your own dependency audit now, rather than waiting for the open weights to make this trivial for someone else to replicate. Two weeks ago GLM-5.2 was topping open-weights leaderboards on coding alone; now the same lineage is finding bugs faster than most security teams can patch them. OpenAI paused its own next model, Astra, over a similar cyber-capability threshold it wouldn’t name. Read that story next if you want the fuller pattern.
- 01Z.ai Launches GLM-5.3 With Frontier Coding and a Cyber Capability That Outgrew Its Trainingunite.ai · reporting on Z.ai's announcement
- 02GLM-5.3: Post-Training Produced Exploit Chains Z.ai Never Planned, Finds 1,097 Critical Bugstechtimes.com · independent reporting
