cd /news/artificial-intelligence/glm-5-3-identifies-serious-vulnerabi… · home topics artificial-intelligence article
[ARTICLE · art-97429] src=cryptobriefing.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

GLM-5.3 identifies serious vulnerability in Cursor code editor

Z.ai's open-weights model GLM-5.3, released on August 14, 2026, identified a significant vulnerability in Cursor, the AI-powered code editor, according to security researcher Joshua Saxe. The model scored 84.5% on the CyberGym vulnerability discovery benchmark, surpassing Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%), and 54.4% on ExploitBench, nearly double its predecessor GLM-5.2. Since GLM-5.2, Z.ai's models have found 2,436 vulnerabilities across 269 projects, with 1,097 classified as critical or high severity, including some undetected since 1981.

read2 min views1 publishedAug 14, 2026
GLM-5.3 identifies serious vulnerability in Cursor code editor
Image: Cryptobriefing (auto-discovered)

Via blog.skillfactory.ru

Z.ai's new open-weights model topped cybersecurity benchmarks and found a critical flaw in one of AI coding's most popular tools

An AI model just found a serious security flaw in the software that developers use to write AI-assisted code.

Z.ai released GLM-5.3 on August 14, 2026, and the model’s headline moment came quickly: it identified a significant vulnerability in Cursor, the AI-powered code editor. The discovery was flagged by security researcher Joshua Saxe.

The benchmark numbers tell a story #

On the CyberGym vulnerability discovery benchmark, the model scored 84.5%, edging out Mythos 5 at 83.8% and GPT-5.6 Sol at 83.6%.

The ExploitBench results are where things get genuinely striking. GLM-5.3 scored 54.4% on that benchmark, which measures a model’s ability to reason through and execute exploits. Its predecessor, GLM-5.2, scored roughly half that.

Z.ai attributes the entire improvement to post-training reinforcement learning in security-focused environments. The base model itself was not changed.

2,436 vulnerabilities and counting #

Since Z.ai introduced GLM-5.2, its models have collectively identified 2,436 vulnerabilities across 269 projects. Of those, 1,097 are classified as critical or high severity.

The scope of what these models have found spans kernels, operating systems, browsers, and protocols. Some of the vulnerabilities discovered had gone undetected since 1981.

GLM-5.3 also offers users flexibility in how much cognitive effort the model applies to a given problem, with settings for low, high, or maximum thinking effort. The feature cannot be disabled entirely.

Open weights, delayed by safety review #

Z.ai released GLM-5.3 as an open-weights model, meaning external researchers and developers can download and run it without routing everything through a proprietary API.

The open-weights release was delayed by two weeks to allow for a safety evaluation. A model that can identify and reason about exploits at this performance level is, almost by definition, a dual-use tool.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #artificial-intelligence 4 stories · sorted by recency
tokenstead.ai · · #artificial-intelligence
GLM 5.3
── more on @z.ai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/glm-5-3-identifies-s…] indexed:0 read:2min 2026-08-14 ·