MDL-1702EST.2026 · IDX.423
Language modelIn production

GLM-5.3

Z.ai (Zhipu AI) · China · 2026

Same base model as GLM-5.2, all gains from post-training — and a cyber capability its makers say surprised them: 2,436 real vulnerabilities found in open-source code.

wujec.ai score

/10

Community score

no votes yet
Sign in to rate

GLM-5.3 is Z.ai's flagship model, published on 14 August 2026. Its most unusual feature is what it is not: it is not a new model. Z.ai states plainly that GLM-5.3 runs on the same base as GLM-5.2 and that every improvement comes from post-training. The company's own numbers show what that alone can buy — Terminal-Bench 3.0 rises from 4.6 to 28.3, DeepSWE v1.1 from 46.2 to 66.9, Agents' Last Exam (CLI) from 23.8 to 28.5, and on the in-house Z.ai Code Bench the model reaches 34.5% at roughly 75,000 output tokens per task against 23.4% at 96,000 for its predecessor: better results while spending fewer tokens. The surprise, by Z.ai's own account, was security. Vulnerability-discovery environments were added to the training mix in the expectation of modest gains; what emerged instead was a model that reasons across whole exploitation chains. On CyberGym it scores 84.5%, up from 77.2%, narrowly ahead of Claude Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%). Deeper into the chain the picture reverses: on ExploitBench GLM-5.3 more than doubles its predecessor to 54.4% but remains far behind Mythos 5 (78.0%) and Sol (76.5%), and on ExploitGym it completes 105 tasks in two hours against Mythos 5's 181. Z.ai says so itself: capability grows fastest exactly where the gap to the closed frontier is widest. Two caveats matter for anyone planning around this model. First, at launch it was not downloadable — Z.ai promised weights "in two weeks" and marked the API as coming soon, so for now access runs through the GLM Coding Plan subscription and the ZCode agent. Calling it the number one open-source model while the weights are still unpublished is a claim about the near future, not the present. Second, GLM-5.3 no longer accepts thinking.type: disabled; applications that switched thinking off must set a reasoning effort level before migrating, or the request fails.

#open weights#coding#1M context#MoE#cybersecurity
Official website

News

Videos

No videos yet.

Reviews

No reviews yet. Be the first!

Sign in to write a review