Back to news
researchZhipuCursor2026-08-14

Zhipu GLM-5.3 found what it calls a serious vulnerability in Cursor during reverse-engineering testing

During reverse-engineering testing around the August 14 launch of GLM-5.3, Zhipu identified what it characterizes as a potentially serious vulnerability in the AI coding tool Cursor and disclosed it in a controlled manner. The finding emerged as the cybersecurity capability expanded beyond single-bug reasoning into exploit-chain reasoning.

Following the August 14 release of GLM-5.3, Zhipu disclosed that during reverse-engineering testing around the launch it identified what it characterizes as a potentially serious vulnerability in the AI coding tool Cursor, and reported it within a controlled disclosure process. Zhipu described the finding as an unintended byproduct of post-training-scaled cybersecurity capability.

Zhipu's training originally targeted single-vulnerability reasoning, but as training scale grew, the model acquired multi-step exploit-chain reasoning, autonomously completing full attack paths from identification through exploit construction. On the CyberGym benchmark, GLM-5.3 scored 84.5 percent, ahead of Anthropic Claude Mythos 5 at 83.8 percent and OpenAI GPT-5.6 Sol at 83.6 percent.

On safety grounds Zhipu delayed open-weight release by roughly two weeks, targeting around August 28, citing the model's reasoning capability exceeding its training objectives. In a real-world program with Chinese security partners, GLM-5.3 has surfaced 2,436 vulnerabilities across 269 projects, of which 1,097 are rated critical or high-severity, spanning Linux, WebKit and FreeBSD, with some undetected for decades and 53 already disclosed. Industry observers see this as the first time an open-weight model has overtaken mainstream closed frontier models on a cybersecurity benchmark.

ZhipuGLM-5.3网络安全漏洞Cursor