Another focus of GLM-5.3 is cybersecurity. Zhipu, in collaboration with Tsinghua and Nankai universities, conducted red-team testing, discovering a total of 2,404 vulnerabilities (after initial screening and deduplication), of which 1,088 were medium to high severity, covering 220 projects. The Decoder's report, however, states that GLM-5.3 helped security teams find 2,436 vulnerabilities across 269 projects, with the oldest dating back about 40 years.
In ExploitGym testing, GLM-5.3 completed 130 out of 898 tasks within 6 hours, matching Claude Mythos 5's performance. Qbit's hands-on test showed GLM-5.3 identifying all 12 vulnerability types in the AegisDesk project and fixing them itself, with all 54 regression tests passing in the end.
Notably, the specific methods and verification processes for vulnerability discovery have not been fully disclosed; for example, the discrepancy between 2,404 and 2,436 may stem from different statistical criteria. Additionally, Qbit's test is media testing, not an independent third-party evaluation, so its conclusions should be treated with caution.