# Cursor Quietly Adds Zhipu's GLM 5.3 Right After It Found a Bug in Cursor

> Source: <https://startupfortune.com/cursor-quietly-adds-zhipus-glm-53-right-after-it-found-a-bug-in-cursor/>
> Published: 2026-10-02 00:24:10+00:00

*Cursor quietly added Zhipu AI's GLM 5.3 to its model picker, the same model that exposed a serious security flaw in the editor. No press release, no partnership announcement, only a new line in the settings menu.*

Z.ai, the company formerly known as Zhipu AI, released GLM 5.3 on August 14, 2026. Weeks later, Cursor quietly listed it as a supported model, reachable through Settings > Models, according to Cursor's own documentation page for the model. There was no joint announcement, no blog post from either company explaining the decision. Developers found out the way they usually find out about these things on Cursor: by checking the settings menu and the community forum.

The pricing is the real story here. GLM 5.3 runs $1.40 per million input tokens and $0.26 per million output tokens, with flat pricing across its full 1 million token context window and no long-context surcharge or cache-write fee, per Cursor's documentation. Compare that to what Cursor itself charges for frontier Western models and the gap is obvious. GLM 5.3 also comes with three selectable reasoning levels, Low, High, and Max, with High set as the default, and full access to Cursor's agent tools: file search, image generation, the works.

Here's the part that makes this stranger than a routine model add. Days after GLM 5.3 launched, VentureBeat reported that the model had identified a serious vulnerability in Cursor itself, a weakness in how the editor is built that could let an attacker write files anywhere on a user's machine. So the model Cursor just welcomed into its product is the same model that went looking for holes in that product and found one. Cursor didn't make a thing of it publicly. It just kept shipping the integration.

Cursor has a track record here, and it's not a flattering one. Its own Composer 2 model, released in March 2026, turned out to be a fine-tuned version of Kimi K2.5, an open-weight model from Beijing-based Moonshot AI. Cursor didn't disclose that. A developer caught it by intercepting a model ID in Cursor's API traffic, a string reading kimi-k2p5-rl-0317-s515-fast, and only after that leaked through developer channels did Cursor acknowledge what was underneath its own branding. Composer 2.5, released in May 2026, runs on the same Kimi K2.5 base, trained with 25 times more synthetic tasks, and Cursor prices it at $0.50 per million input tokens, roughly a tenth of what Claude Opus 4.7 costs.

[Anthropic warns a free Chinese AI model can already build working hacks](https://startupfortune.com/anthropic-warns-a-free-chinese-ai-model-can-already-build-working-hacks/)

Anthropic's own research shows Z.ai's freely downloadable GLM-5.3 model can autonomously build working cyberexploits, with safety filters that fail 64% to 100% of the time in tests. The finding lands the same week Anthropic's IPO filing warns investors that AI poses an existential risk to humanity. - [free Chinese AI model builds working cyberattacks](https://startupfortune.com/anthropic-warns-a-free-chinese-ai-model-can-already-build-working-hacks/) - [how to autonomously generate exploit code with AI](https://startupfortune.com/anthropic-warns-a-free-chinese-ai-model-can-already-build-working-hacks/)

That's the pattern. Cursor doesn't need to tell anyone where its intelligence comes from, because nothing in Kimi K2.5's license requires it. Composer's attribution problem wasn't illegal. It was just the kind of thing a company only admits once it's already been caught. GLM 5.3 didn't need to be smuggled in the same way, since Z.ai is open about what it ships, but Cursor's own silence around adding it fits the same habit: route around the expensive frontier labs, say as little as possible about it, let the settings menu do the talking.

The competitive logic is straightforward even if Cursor won't say it out loud. GPT and Claude-based coding assistance costs real money at scale, and Cursor's business depends on agents burning through tokens continuously, not the occasional chat completion. A model that's meaningfully cheaper and still competitive on raw capability changes the unit economics of every long agentic coding session. Z.ai's own benchmarks claim GLM 5.3 scored 94.2% on SWE-bench Verified under an external evaluation framework, and that it beat Gemini 3 Pro and GPT-5.2 on SWE-bench Multilingual. Whether those numbers hold up under independent scrutiny matters less to Cursor than the fact that developers now have the option, sitting right next to GPT and Claude in the same dropdown, at a fraction of the cost.

This also isn't limited to GLM. Cursor already supports DeepSeek and Qwen through OpenAI-compatible custom model configuration, and Kimi sits underneath its own in-house Composer line. Add GLM 5.3 to the picker and you get a coding editor that, model for model, now leans more on Chinese labs than American ones for anything beyond its flagship chat experience. Windsurf and GitHub Copilot have been slower to formalize this kind of multi-vendor flexibility, which gives Cursor a real edge with developers who care more about cost per token than brand loyalty to OpenAI or Anthropic.

None of this requires a partnership announcement because there isn't a partnership. It's commodity pressure. Cursor needs cheap, capable models to keep its agent economics working, and it will take them from wherever they're good enough, publish a quiet docs page, and move on. The company that found a hole in Cursor's own code is now one of the models you can ask to write your next pull request.

**Also read:** [Thieves stole an Nvidia branded trailer full of sand, not the GPUs they wanted](https://startupfortune.com/thieves-stole-an-nvidia-branded-trailer-full-of-sand-not-the-gpus-they-wanted/) • [Why Enterprise Media Stays Unorganized, and the Engineer Who Built a Model to Fix It](https://startupfortune.com/why-enterprise-media-stays-unorganized-and-the-engineer-who-built-a-model-to-fix-it/) • [Broadcom Agreed to Lend Anthropic Up to $42 Billion Ahead of Its IPO](https://startupfortune.com/broadcom-agreed-to-lend-anthropic-up-to-42-billion-ahead-of-its-ipo/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

[Z.ai launches GLM-5.3, a coding model billed as ready for cyber defense](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/)

Z.ai launched GLM-5.3, its new flagship open-weight model, with the tagline "Built to Code. Ready for Cyber Defense." The launch follows a NIST assessment that found its predecessor, GLM-5.2, matched Claude Opus 4.6 on cyber capability while its safeguards allowed help with exploit development. - [GLM-5.2 model cyber defense capabilities](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/) - [open weight coding model security](https://startupfortune.com/zai-launches-glm-53-a-coding-model-billed-as-ready-for-cyber-defense/)

## Join the discussion

[Open in the community →](https://startupfortune.com/community/)

Almost there. Sign in and your reply posts straight away.
