Tools AI Risk Radar ai-incident-0038
Incident record
Z.ai holds back GLM-5.3's open weights after the model's exploit chaining outgrew its training
- Severity
- High
- Status
- Research
- Type
- AI-Found Vuln
- Target
- Linux, WebKit, FreeBSD and 266 further open source projects
- Actor
- researcher
What happened
Z.ai said post-training scaling made its new open-weight coding model GLM-5.3 develop cyber capability faster than expected: rather than only spotting isolated flaws, it began reasoning across multiple stages of exploitation and forming complete attack chains, more than doubling GLM-5.2's score on its own ExploitBench benchmark, from 24.4 to 54.4 per cent. Working with security teams against real codebases, the company said the model surfaced 2,436 vulnerabilities across 269 projects, 1,097 of them of medium to high severity, some undisclosed for decades.
Z.ai is holding back GLM-5.3's open weights for two weeks after launch, while the model stays available through its own API and coding plan, so safety evaluation and hardening can finish first; the company frames this as its first cyber-capability-driven release delay, and has built a public Security Disclosure Ledger to track the findings through responsible disclosure. This is Z.ai's own account of its model's capability and has not been independently verified.
Sources
- Z.ai: GLM-5.3, frontier coding with emergent cyber capabilitiesz.ai/blog/glm-5.3
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026