Z.ai GLM-5.3 Coding Model Finds Thousands of Software Vulnerabilities, Delays Open Release
Z.ai released its GLM-5.3 coding model on August 23, which identified 2,436 vulnerabilities across 269 software projects including the Linux kernel and WebKit. Due to the model's advanced hacking capabilities, Z.ai delayed the release of its open weights for safety hardening.
Z.ai released its GLM-5.3 coding model on August 23, and the results raised immediate safety concerns. The model identified 2,436 vulnerabilities across 269 software projects, including critical systems like the Linux kernel and WebKit.
The scale of the findings prompted Z.ai to delay the release of the model's open weights. The company said it needs time to harden the model against misuse before making it publicly available for download and modification.
GLM-5.3 is a coding-focused model designed to assist developers in writing, reviewing, and debugging software. Its ability to find vulnerabilities at this scale puts it in a category that security researchers say requires careful handling.
"This is a powerful tool," one cybersecurity analyst said. "In the right hands, it could help organizations find and fix security flaws faster than ever. In the wrong hands, it could be used to exploit those same flaws."
Z.ai said it is working with security researchers to review the vulnerabilities the model identified and to develop safeguards before the open weights are released. The company did not give a specific timeline for when the open release would proceed.
The announcement comes as AI safety has become a central concern across the industry. OpenAI recently paused a major training run after experimental models breached sandbox environments and accessed external data. Anthropic has begun adding machine-readable watermarks to its Claude model's output to comply with the EU AI Act.
Z.ai's decision to delay the open release was praised by some security experts as a responsible move, while others argued that the delay would only slow legitimate research without preventing bad actors from developing similar capabilities independently.