The Chinese startup Z.ai has unveiled its latest language model, GLM-5.3. This new version features enhancements in programming, agent scenarios, and vulnerability detection.
Source: Z.ai.Z.ai stated that the improvements over GLM-5.2 were achieved solely through post-training techniques, without altering the foundational model.
The open weights of the model will be made available two weeks after a security assessment and additional hardening processes.
In its internal benchmark, known as Code Bench, GLM-5.3 outperformed its predecessor by 50% in coding tasks.
Z.ai provided a comparison of several tests in its release notes:
- Terminal Bench 3.0 — 28.3 points versus 4.6 for GLM-5.2;
- DeepSWE v1.1 — 66.9 compared to 46.2;
- Agents' Last Exam — 28.5 against 23.8;
- CyberGym — 84.5% versus 77.2%;
- ExploitBench — 54.4% compared to 24.4%.
Notably, in the ExploitGym test, the model successfully resolved 105 tasks within a two-hour limit, compared to just 29 for GLM-5.2. This number increased to 130 tasks in a six-hour timeframe, up from 39 in the earlier version.
Another significant aspect of the release involved testing on real codebases in collaboration with various security teams in China. Z.ai reported that after verification and deduplication, the system identified 2,436 vulnerabilities across 269 projects, including 1,097 issues classified as medium to high severity.
Source: Z.ai.Of these findings, 53 have been publicly disclosed, while 2,383 remain under embargo. The average lifespan of these vulnerabilities is estimated at 26.6 years, with the oldest dating back to 1981.
To track the disclosure of these findings, Z.ai has launched the Z.ai Security Disclosure Ledger, a public registry that records the status, affected projects, and severity ratings, if assigned.
Additionally, there has been an update to the product offering. GLM-5.3 is now available for subscribers of the GLM Coding Plan, being promoted as the primary engine for agent-based programming and "long" tasks. Requests directed to older models are automatically routed to the new version.
It is worth noting that in July, Anthropic accused Z.ai of unauthorized distillation of GLM-5.2 based on responses from Claude and GPT.
