Skip to content
New version of the open-weight model: GLM 5.3 improves security capabilities

New version of the open-weight model: GLM 5.3 improves security capabilities

Heise.De August 14, 2026

The Chinese AI company z.ai has released the latest version of its open-weight model, GLM 5.3. The model builds on the training data of its predecessor – the company made all improvements after training. These are mainly in source code development and cybersecurity: the new version is the most capable open-weight model for software development and has more than doubled its security performance, its creators claim.

The manufacturer has primarily improved its model with “Environment Scaling”, i.e., by having it solve a series of artificially generated tasks. In doing so, z.ai also included tasks that would take an experienced software developer several working days. In benchmarks such as Terminal Bench 3.0, SWE-Marathon, and FrontierSWE, GLM 5.3 shows significant improvements over its predecessor in some cases and keeps pace with the top performers, namely the Frontier models from Anthropic and OpenAI.

The new model is also expected to perform better than its predecessor as a security researcher. It should not only detect simple vulnerabilities but also multi-stage exploit chains. In the CyberGym benchmark, which tests the detection of simple security flaws through source code analysis, GLM 5.3 narrowly beats the second-placed Mythos 5 by almost half a percentage point. However, in ExploitBench and ExploitGym, the model still lags behind the competitor from Anthropic. But according to z.ai, performance has also taken a leap in the complex tasks of these benchmarks.

In collaboration with various security researchers from China, z.ai then examined real source code and discovered a total of 2436 new security vulnerabilities in nearly 270 projects. More than 100 of these are critical, for example in the Linux kernel, WinRAR, Redis, or FFmpeg. The majority of the vulnerabilities remained undiscovered for years; the oldest security vulnerability is 45 years old. In its „Vulnerability Ledger“ , the AI company displays statistics and provides information the vulnerabilities. However, details are only available for four dozen of them – most of the other errors have not even been reported to the responsible developers by the finders so far.

An interesting project based on GLM 5.3 is also OpenVuln . Apparently, z.ai offers software developers a security check of their projects here – at what price, however, is unclear. Those who manage a project on GitHub can simply provide the URL to the repository and “OpenVuln hunts down its vulnerabilities”, z.ai promises.

Anyone who wants to use GLM 5.3 in their daily work can currently only do so as a paying customer of z.ai: Those who have booked a subscription to the “z.ai Coding Plan” or use the company's own harness ZCode can already select the new model. Because although it should be available for download on HuggingFace as an “Open Weight” model like its predecessors, the manufacturer is postponing the release date. “We will release the weights two weeks after launch, once the security evaluation and hardening are complete”, z.ai writes in its announcement under the probably mistakenly chosen keyword “Open Source”.

The security of frontier models is currently a hot topic. After it became known that an AI had attacked HuggingFace , the British AI Safety Institute is also involved in similar incidents. It observed Mythos and GPT-5.6-Sol lying , social engineering, and phishing against open-source maintainers during a lab experiment. In a webinar, we will explain to you at the beginning of October: How to defend yourself against attacking AI agents .

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

MITRE ATT&CK (1)