Z.ai’s GLM-5.3 has now reported 4,249 vulnerabilities across 389 open-source projects, up from 1,097 findings across 269 projects when the model launched in August. OpenVuln, the service behind the count, is free, still running, and delivers every finding to maintainers privately instead of disclosing them for reach. Zixuan Li, who leads the GLM team at Z.ai, published the counter on September 30:
The week that tested the same weights three ways
Anthropic’s Frontier Red Team published a dedicated assessment of GLM-5.3 on September 29, “GLM-5.3 and the spread of advanced cyber capabilities.” The offensive-side numbers are the ones that made headlines: on ExploitBench, where a model must build a working end-to-end exploit for a real V8 vulnerability, GLM-5.3 succeeded in 50 of 410 attempts while Claude Mythos Preview, Anthropic’s own exploit-capable flagship, succeeded in 56 of 410, a 12 percent versus 14 percent pairing that puts an open model within two points of the closed frontier on this benchmark. Opus 4.6 and GLM-5.2 scored zero. Kimi K3 scored 0.5 percent and DeepSeek V4.1-Flash 0.2 percent. NIST’s CAISI, which ran its own assessment the week before, called GLM-5.3 “the most cyber-capable open-weight model released to date” and put the open-weight field about four months behind the US frontier in aggregate.
The audit exists because the weights are open
The report’s other headline: GLM-5.3’s safeguards are bypassable “between 64 and 100 percent of the time”, a finding reachable only in one direction. Abliteration, the technique that cut GLM-5.3’s refusal rate from above 90 percent to about 3 percent on the first two benchmarks, is an operation on weights. You cannot run it against a closed API. The same audit showed Anthropic’s safeguarded Claude models holding out, and showed nothing at all about Claude’s closed side, because there is nothing to test. Openness is what makes the weakness findable, fixable at the community level, and quantifiable at all; it is also what makes the model usable by anyone. Both halves are true, and Anthropic’s report states both.
The defense ledger, growing while the warning traveled
The same model is the engine behind two running defense stories this site has tracked since August. OpenVuln’s 4,249 findings flow to maintainers with an explicit design choice: results stay private to the project until patched, so nobody buys exploit reach with Z.ai’s work. The receipts predate the counter: Hugging Face reconstructed the July breach of its own systems from an action log of more than 17,000 events, and ran that reconstruction on GLM 5.2 self-hosted, after the commercial models it reached for first declined the work. Anthropic’s report does not mention that incident, but its shape matters: when an active breach needs unguarded model capability for forensics, the defender’s option is the open download.
Ahmad Osman put the two halves together the same day, with the rescue tweet drawing 1,788 likes:
One attribution caution on the viral framing: the published accounts say “the commercial models Hugging Face reached for first declined the work” and name no vendor. The claim that Anthropic or OpenAI specifically refused is inference, not reporting.
The commercial offshoot, 24 hours later
The proliferation prediction landed on schedule. OrcaRouter, an inference-router company, announced OrcaCyber Zero 1.0 on September 29: GLM-5.3 post-trained for vulnerability research, exploit reproduction, and red-team workflows, sold through its API at $3 per million input tokens and $5 per million output. The company cites 98 percent pass@1 on CyberGym Level 1 (1,478 of 1,507 real-world vulnerability-reproduction tasks), a vendor-run number with no published methodology, absent from the official leaderboard, where the tracked leader sits at 95.1 percent (MiMo-V2.6-Flash). Two flags, stated plainly: the tweet and the company’s own model page print different figures (98.01 versus 98.07) for the same run, and CyberGym Level 1 is the shallow end of offense: reproduce a known vulnerability from its description and unpatched codebase. It is real capability, not the tier Anthropic benchmarked GLM-5.3’s frontier-adjacent attack breadth on. Anthropic’s warning chapter of the report, written about open weights and misuse boundary, got its first commercial test case within a day.
The honest read
One model, one week, three measurements. Anthropic measured the offensive edge and found it within two points of its own flagship, with no enforceable misuse boundary. NIST’s CAISI measured the aggregate and found the open field four months behind with the gap closing. Field operators measured the defensive edge and found the largest running bug-hunt in the open-weights lane, delivered privately for free. The local-AI reality this site tracks is that all three are the same download: 1.37 million people have pulled it. A rig that serves GLM-5.3 is a dual-use box, and the gate you put on it is yours, which is the actual sovereignty argument, arrived at a speed few predicted: not someday, this quarter.
Sources: - Z.ai OpenVuln space - Zixuan Li, September 30 - Anthropic, GLM-5.3 and the spread of advanced cyber capabilities, September 29 - NIST CAISI assessment, September 17 - Ahmad Osman, September 29 - OrcaRouter, OrcaCyber Zero 1.0 - CyberGym leaderboard
Related on this site: GLM-5.3: the coding upgrade - AI agent liability: contracts, insurance, and the gap
Discussion
Be the first to commentStart a discussion
Got a take on this, a rig to show off, or a benchmark that says otherwise? Sign up and start the thread - your comment publishes instantly once you're in.