GLM-5.3 is an open-weight AI model from the Chinese lab Z.ai (Zhipu AI). It was released on August 14, 2026 as a coding model, and its weights followed about two weeks later. Since then, two independent reports have said the same uncomfortable thing: the model is good at finding and exploiting software vulnerabilities, and the safeguards meant to stop misuse do not hold.
This article explains the GLM-5.3 cybersecurity issue in plain terms: what was measured, who measured it, what is still disputed, and what a developer or small team should change.
The short version
- The issue is not a bug in GLM-5.3. It is a capability. The model can find unknown vulnerabilities and turn them into working exploits.
- The safeguards are weak. In Anthropic’s tests, simple tricks got the model to help with harmful cyber tasks 64% to 92% of the time. With the refusals removed from the weights, it helped 100% of the time.
- The weights are public. Anyone can download the model, so restrictions on a hosted API do not limit what a determined attacker can do.
- It is still behind the best closed models. The U.S. government’s own assessment puts it about four months behind the U.S. frontier.
What is GLM-5.3?
GLM-5.3 is the latest model in Z.ai’s GLM family, built for long coding and agent tasks with a one-million-token context window. It first shipped through Z.ai’s paid coding plan, and the open weights were published on Hugging Face afterwards, under a custom GLM-5.3 licence.
Z.ai itself drew attention to the security side at launch. According to VentureBeat’s launch coverage, the company said cyber capability “developed faster than we expected” during training. It reported 2,436 vulnerability findings across 269 real projects after expert review, with 1,097 rated critical or high severity. Only 53 were public at launch; the rest were under embargo while maintainers fixed them.
A Z.ai developer advocate also said the model had found a potentially serious vulnerability in the Cursor code editor. No technical details were published, and that claim had not been confirmed by Cursor at the time of the report.
What Anthropic’s report found
On September 29, 2026, Anthropic’s Frontier Red Team published an analysis of GLM-5.3’s cyber capabilities. It makes two separate claims.
Claim 1: the model can build real exploits
| Test | GLM-5.3 | Claude Mythos Preview | Earlier models |
|---|---|---|---|
| ExploitBench (Chrome V8 bugs) | 50 of 410 (12%) | 56 of 410 (14%) | About 0% |
| Binary exploitation (100 OSS-Fuzz tasks) | 4% | 6% | 0% |
The percentages look small. The important part is the last column: models from a generation earlier could not do this at all.
The report also describes two hands-on demonstrations:
- With a researcher guiding it for under an hour of attention across about a day, GLM-5.3 found several unknown flaws in a browser’s JavaScript engine on Linux and chained them into a web page that could read files from a visitor’s computer. Anthropic says it reported the flaws to the maintainer.
- The smaller GLM-5.3-Flash turned the public details of a known Chrome flaw into a working exploit chain. That took about 20 minutes of human attention, eight hours of model time, and roughly $20 in API cost.
Claim 2: the safeguards are easy to bypass
Anthropic measured how often the model agreed to help with a harmful cyber task:
| Approach | Model helped |
|---|---|
| Plain malicious request | 0% |
| False cover story, such as claiming to be authorised | 64% |
| Prefilled reasoning | 92% |
| Refusals removed from the weights | 100% |
The last row matters most for an open-weight model. Removing refusal behaviour from downloaded weights, often called abliteration, took Anthropic about 2,200 GPU hours, or about $4,400. It estimates an experienced team could do it for about $1,200. The modified model kept almost all of its ability.
In other words, refusal training slows down a casual user. It does not stop someone with a few thousand dollars and the weights.
What NIST found
The U.S. Center for AI Standards and Innovation (CAISI), part of NIST, published its own assessment on September 17, 2026. It called GLM-5.3 “the most cyber-capable open-weight model released to date”, and also said its capabilities are “significantly lower” than current U.S. frontier models.
| Benchmark | GLM-5.3 | U.S. frontier | Other PRC frontier |
|---|---|---|---|
| SEC-Bench Pro | 40.4% | 90.2% | 27.3% |
| ExploitBench | 61.1% | 100.0% | 32.2% |
| ExploitGym | 9.4% | 44.4% | 2.6% |
| OSS-Fuzz | 7.7% | 23.2% | 2.4% |
CAISI estimated the gap to the U.S. frontier at about four months. Its numbers differ from Anthropic’s because the test setups differ, so compare the columns inside each table rather than across reports.
What is disputed
It is worth reading these reports with some care.
- Anthropic competes with Z.ai. Many developers pointed out the conflict of interest, and some read the report as an argument against open-weight models in general. The NIST assessment is independent of Anthropic and reaches a similar conclusion on capability, but it did not test safeguards.
- The tests are not real attacks. Anthropic says its simulated environments are imperfect, the human-guided sessions were short, and the browser exploit targeted Linux builds only.
- The same skills are used for defence. Finding and proving vulnerabilities is everyday work for security teams. Z.ai’s own launch numbers came from finding bugs so they could be fixed.
- Some claims are unverified. The Cursor vulnerability and most of Z.ai’s 2,436 findings have no public technical details yet.
A fair summary: the capability is real and confirmed by two sources, the weak safeguards are well documented by one source, and how much this changes real-world attacks is still an open question.
What developers should do
You do not need to be a security specialist to act on this. The practical lesson is that the cost of finding and exploiting a known bug has dropped, so the time between a patch being published and an attack appearing gets shorter.
- Patch faster. A public fix now doubles as a recipe. Turn on automatic dependency updates and treat browser, runtime, and framework updates as urgent.
- Do not treat a model refusal as a security control. If your product relies on a model saying no, assume a user can get it to say yes. Put the real limit in code: permissions, rate limits, and input validation.
- Sandbox AI coding agents. Give an agent a scoped token, a restricted file system, and limited network access. Review what it can reach before pointing it at a production system.
- Be careful with modified weights. If you self-host an open model, download it from the official repository and verify checksums. Community builds with “uncensored” in the name have had their safety behaviour removed on purpose.
- Use the same tools on your own code. Models at this level are useful for reviewing your own project for vulnerabilities. Only test systems you own or have written permission to test.
- Check the licence. GLM-5.3 uses a custom licence rather than a standard open-source one, so read it before shipping the model in a commercial product.
Should you stop using GLM-5.3?
Not for this reason alone. The reports describe what an attacker could do with the model. They do not say the model is unsafe to run for ordinary coding work, and they do not describe a vulnerability in your application caused by using it.
The usual questions still apply to any model: where your code and data are sent, what the licence allows, and how much access the agent has. If you are designing an AI feature of your own, the same thinking applies to the interface: plan for the request that fails or needs to be stopped, as covered in AI streaming UX: loading, stop, retry, and error states.
Frequently asked questions
Is GLM-5.3 safe to use for coding?
For normal development work, the reports do not show a specific risk to your project. The concern is misuse by attackers. Apply the same care as with any AI agent: limit its permissions and review its changes.
Was GLM-5.3 hacked?
No. The “cybersecurity issue” is that the model is capable of offensive security work and its safeguards against misuse can be bypassed. It is not a breach of Z.ai or a flaw that exposes its users.
What does “open-weight” mean, and why does it matter here?
Open-weight means the trained model files can be downloaded and run on your own hardware. That gives developers control and privacy, and it also means the publisher cannot enforce usage rules or withdraw access after release.
Is GLM-5.3 as capable as closed frontier models?
No. NIST’s CAISI estimated it is about four months behind the U.S. frontier on cyber benchmarks. It is the strongest open-weight model on those tests so far.
Sources
- Anthropic Frontier Red Team: GLM-5.3 and the spread of advanced cyber capabilities, September 29, 2026
- NIST CAISI: Assessment of Z.ai’s GLM-5.3 cyber capabilities, September 17, 2026
- VentureBeat: GLM-5.3 launch coverage
- Hugging Face: GLM-5.3 model card