VentureBeat·—
GLM-5.3 is here with advanced cyber capabilities — and reportedly already found a 'serious vulnerability' in Cursor
Z.ai has released GLM-5.3, an advanced language model with improved long-horizon coding capabilities and enhanced cybersecurity features. The model uses the same base model as GLM-5.2 but with significant gains from scaling post-training across more environments and tasks. GLM-5.3 has already identified a "potentially serious vulnerability" in Cursor, an AI coding startup acquired by SpaceX.
GLM-5.3's cybersecurity capabilities improved faster than expected, particularly in exploiting software flaws. The model scores 84.5% on CyberGym, a benchmark for vulnerability discovery and validation, and 54.4% on ExploitBench, outperforming its predecessor GLM-5.2. However, it lags behind other models like GPT-5.6 Sol and Mythos 5 on ExploitGym.
Z.ai has introduced controls around GLM-5.3's advanced capabilities, including a "trusted access" approach for sensitive functionality. The company also emphasizes efficiency over benchmark performance, with GLM-5.3 consuming fewer output tokens while achieving better task completion results.
GLM-5.3 is available through the GLM Coding Plan and ZCode coding environment, with API access and open weights coming later. Developers migrating existing GLM applications should note that GLM-5.3 requires a different API behavior, and applications currently sending "thinking.type: 'disabled'" must change the value to "enabled" and specify a reasoning effort before switching to GLM-5.3.
Z.ai's focus on coding agents and long-running autonomous engineering workloads continues with GLM-5.3, building on the direction set by GLM-4.5 and GLM-5. The company's rapid shift toward agentic engineering and long-horizon tasks is evident in its recent model releases, with GLM-5.3 representing a significant step forward in this area.