GLM-5.3 finds 'serious' Cursor flaw — Z.ai withholds open weights for safety

GLM-5.3 finds 'serious' Cursor flaw — Z.ai withholds open weights for safety

Chinese AI startup Z.ai has released GLM-5.3, the latest iteration of its largely open-source GLM family of language models. The new version brings substantial gains in long-horizon coding and, more consequentially, a jump in cybersecurity capabilities that the company is treating with visible caution.

According to Lou, a developer advocate at Z.ai, GLM-5.3's cyber abilities have already uncovered a "potentially serious vulnerability" in Cursor, the AI coding tool recently acquired by SpaceX. Lou shared the finding on X, and VentureBeat has reached out to Cursor for confirmation but has not yet received a response.

The model is initially available only through Z.ai's GLM Coding Plan and the ZCode coding environment. API access and open weights are being held back "until safety evaluation and hardening are complete," the company said. Weights are expected to be released roughly two weeks after launch.

For enterprise developers, the release is notable less for benchmark numbers than for what it represents. Z.ai says GLM-5.3 is built on the same base model as GLM-5.2, with all improvements coming from scaling post-training across more environments, a wider variety of tasks, and additional reinforcement-learning compute. In other words, the company is testing how far a frontier-scale base model can be pushed without another expensive pretraining cycle — and, by extension, whether post-training scaling alone can deliver meaningful capability gains.

The cybersecurity angle adds a layer of complexity. By demonstrating that GLM-5.3 can autonomously identify real-world vulnerabilities, Z.ai is showcasing a capability that is both commercially valuable and potentially dangerous in the wrong hands. The delayed release of open weights suggests the company is aware of the dual-use nature of the model and is trying to balance transparency with safety.

The move also positions Z.ai in a competitive race with other frontier labs, where coding and security are increasingly seen as key differentiators. Whether GLM-5.3's post-training-only improvements hold up in independent testing remains to be seen, but the early signal is that the approach may have more headroom than many expected.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate