Z.ai confirmed that the open-source weights for the model will be released to the public in two weeks, following the completion of safety evaluations.
The update introduces what the company describes as emergent cyber capabilities, with the model demonstrating a new ability to reason across multiple stages of a digital attack to form complete exploitation chains.
In internal testing and real-world trials with security teams, the model identified over 2,400 vulnerabilities across hundreds of projects, including flaws in system kernels and browser engines that had remained undetected for decades.
These improvements matter to the industry because they signal a shift toward autonomous agents that can take ownership of complex, days-long engineering tasks rather than just completing short snippets of code.
Technically, the model’s performance is powered by "slime," an open-source framework that allows for large-scale asynchronous training and more efficient resource use.
This system enables the model to handle long-horizon tasks—complex operations with many steps and dependencies—more effectively than previous versions.
For users, GLM-5.3 introduces a "thinking" mechanism with three effort levels (low, high, and max), where higher effort levels are specifically recommended for deep coding work.
While the model remains behind some closed-frontier competitors in total task completion, Z.ai reports that it now leads among open-weights models in several key coding and vulnerability discovery benchmarks.