GLM-5.3

Zhipu AI

Parameters

753.3B total / 43.0B active

MoE: total / active

Architecture

MoE with IndexShare sparse attention (DSA) + MTP layer

Released

25.08.2026

License

GLM-5.3 License

Open Weights Commercial Use Multimodal BF16, F8_E4M3, F32 GLM en zh

Input Modalities

text

Output Modalities

text

Context (native)

1,048,576 tokens

Context (extended)

1,048,576 tokens

Openness Index Score 70.0/100

About

GLM-5.3 (zai-org/GLM-5.3) is Z.ai's flagship open-weights coding and cyber-capable model - the same 753B-total / 43B-activated MoE base model as GLM-5.2 (IndexShare sparse attention (DSA) + Multi-Token Prediction layer, 1,048,576-token context), where every gain comes from post-training targeting complex coding and long-horizon agentic tasks. Released August 25, 2026.

It is the most capable open-weights model for coding: a 50% improvement over GLM-5.2 on the in-house Z.ai Code Bench, and open-source SOTA on public benchmarks including Terminal Bench 3.0 and Agents' Last Exam. As post-training scaled, an emergent cyber capability developed faster than expected: GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, more than doubling GLM-5.2 on exploitation benchmarks (ExploitGym, ExploitBench). Thinking budget is controllable via the reasoning_effort parameter (low/high/max, default max), and the chat template's clear_thinking defaults to false for chat scenarios to pass explicitly.

Training Data Same base model as GLM-5.2; every gain comes from post-training targeting complex coding and long-horizon agentic tasks

Benchmark Scores

Benchmark Score Date
Terminal Bench 2.1
coding_agent
97.34%
28.08.2026
Terminal-Bench 3.0
coding_agent
79.00%
28.08.2026
DeepSWE 1.1
coding_agent
88.97%
28.08.2026
NL2Repo
coding_agent
73.38%
28.08.2026
ProgramBench
coding_agent
23.22%
28.08.2026
SWE-Marathon
coding_agent
84.69%
28.08.2026
PostTrainBench
coding_agent
91.13%
28.08.2026
Cybergym
general_agent
92.71%
28.08.2026
ExploitGym (2h)
cybersecurity
45.05%
28.08.2026
ExploitGym (6h)
cybersecurity
38.95%
28.08.2026
Toolathlon Verified
general_agent
90.22%
28.08.2026
Automation-Bench
general_agent
85.00%
28.08.2026
Agents' Last Exam
general_agent
84.43%
28.08.2026
HLE (with tools)
stem_reasoning
95.76%
28.08.2026
GDPVal-AA v2
general_agent
96.61%
28.08.2026
SWE-bench Multilingual
coding_agent
90.30%
28.08.2026
SWE-bench Pro
coding_agent
80.75%
28.08.2026
DeepSWE
coding_agent
92.02%
28.08.2026
SWE Atlas - QnA
coding_agent
85.04%
28.08.2026
SWE Atlas - TW
coding_agent
70.30%
28.08.2026
SWE Atlas - RF
coding_agent
85.46%
28.08.2026
Terminal-Bench 2.1 (Terminus-2)
coding_agent
99.11%
28.08.2026
Harbor-Index
coding_agent
65.13%
28.08.2026
Hy-Backend 2.0 (Internal)
coding_agent
67.09%
28.08.2026
Hy-SWE Max Verified (Internal)
coding_agent
86.26%
28.08.2026
Hy-CompanyBench V2 (Internal)
general_agent
80.89%
28.08.2026
WideSearch
general_agent
93.93%
28.08.2026
$OneMillion-Bench
general_capabilities
86.31%
28.08.2026
DRACO
general_agent
55.13%
28.08.2026
Hy-LifeSearch (Internal)
general_agent
42.04%
28.08.2026
Hy-BrowseComp-Pro2 (Internal)
general_agent
12.84%
28.08.2026
OfficeQA Pro
general_agent
98.57%
28.08.2026
MCP-Atlas
general_agent
94.80%
28.08.2026
Apex-Agents
general_agent
89.78%
28.08.2026
SkillsBench Avg5
coding_agent
94.54%
28.08.2026
JobBench
general_agent
78.79%
28.08.2026
WorkSpaceBench
general_agent
59.52%
28.08.2026
BankerToolBench
general_agent
77.22%
28.08.2026
E-Bench (Internal)
general_agent
71.34%
28.08.2026
E-Bench-Code (Internal)
coding_agent
11.58%
28.08.2026
Hy-FinAgentBench (Internal)
domain_finance
80.74%
28.08.2026
Hy-FinmodelBench v2 (Internal)
domain_finance
78.07%
28.08.2026
BioMysteryBench
stem_reasoning
77.47%
28.08.2026
CritPt (no tools)
stem_reasoning
58.36%
28.08.2026
GPQA Diamond
stem_reasoning
95.08%
28.08.2026
Humanity's Last Exam
stem_reasoning
76.14%
28.08.2026
SUPERChem
stem_reasoning
24.48%
28.08.2026
FrontierSWE
coding_agent
82.94%
28.08.2026
ExploitBench
cybersecurity
55.97%
28.08.2026

Model Tree, Spaces and Paper

Model tree for zai-org/GLM-5.3

Finetunes

3 models

Quantizations

50 models

Spaces using zai-org/GLM-5.3 13

Collection including zai-org/GLM-5.3

[

GLM-5.3

Collection

4 items • Updated 15 days ago • 42

](https://huggingface.co/collections/zai-org/glm-53)

Paper for zai-org/GLM-5.3

[

GLM-5: from Vibe Coding to Agentic Engineering

Paper • 2602.15763 • Published Feb 17 • 221

](https://huggingface.co/papers/2602.15763)

Citation

Citation

If you find GLM-5.3 useful in your research, please cite our technical report:

@misc{glm5team2026glm5vibecodingagentic,
      title={GLM-5: from Vibe Coding to Agentic Engineering},
      author={GLM-5-Team and : and Aohan Zeng and Xin Lv and Zhenyu Hou and Zhengxiao Du and Qinkai Zheng and Bin Chen and Da Yin and Chendi Ge and Chenghua Huang and Chengxing Xie and Chenzheng Zhu and Congfeng Yin and Cunxiang Wang and Gengzheng Pan and Hao Zeng and Haoke Zhang and Haoran Wang and Huilong Chen and Jiajie Zhang and Jian Jiao and Jiaqi Guo and Jingsen Wang and Jingzhao Du and Jinzhu Wu and Kedong Wang and Lei Li and Lin Fan and Lucen Zhong and Mingdao Liu and Mingming Zhao and Pengfan Du and Qian Dong and Rui Lu and Shuang-Li and Shulin Cao and Song Liu and Ting Jiang and Xiaodong Chen and Xiaohan Zhang and Xuancheng Huang and Xuezhen Dong and Yabo Xu and Yao Wei and Yifan An and Yilin Niu and Yitong Zhu and Yuanhao Wen and Yukuo Cen and Yushi Bai and Zhongpei Qiao and Zihan Wang and Zikang Wang and Zilin Zhu and Ziqiang Liu and Zixuan Li and Bojie Wang and Bosi Wen and Can Huang and Changpeng Cai and Chao Yu and Chen Li and Chengwei Hu and Chenhui Zhang and Dan Zhang and Daoyan Lin and Dayong Yang and Di Wang and Ding Ai and Erle Zhu and Fangzhou Yi and Feiyu Chen and Guohong Wen and Hailong Sun and Haisha Zhao and Haiyi Hu and Hanchen Zhang and Hanrui Liu and Hanyu Zhang and Hao Peng and Hao Tai and Haobo Zhang and He Liu and Hongwei Wang and Hongxi Yan and Hongyu

(section continues in the model card)

Footnotes (benchmark methodology)

Footnotes

  • HLE w/ tools: We use sampling parameters of temperature=1.0 and top_p=0.95 for evaluation, with a maximum generation length of 163,840 tokens. The evaluation is conducted with a maximum context length of 300,000 tokens, using a context management strategy. We use GPT-5.6-luna (medium) as the judge model.
  • NL2Repo: We evaluated NL2Repo with temperature=1.0, top_p=1.0, and max_new_tokens=64k under 1M context. To prevent hacking, we use rule-based and a LLM-based judgement to prevent malicious behaviors (e.g., unauthorized pip or curl operations).
  • DeepSWE: We run DeepSWE using the mini-swe-agent harness with temperature=0.95, top_p=1.0, timeout=6h and 400K context.
  • Terminal-Bench 2.1: We evaluate in Claude Code 2.1.207 with temperature=1.0, top_p=1, max_new_tokens=65536 with 6h timeout.
  • Terminal-Bench 3.0: We evaluate Terminal-Bench-3 tasks with the Claude Code 2.1.207 harness (reasoning effort=max, 400K context, and 128K maximum output), reporting avg@3 over three rollouts per task. Each rollout runs in an isolated container built from the task's official image, and is capped at 600 agent turns with a 10-hour timeout. Tool Search is disabled, and the artifacts each agent produces are scored by the task's official separate verifier.
  • Agent's Last Exam (CLI): We evaluate ALE using the official evaluation protocol with the Claude Code harness (reasoning effort=max, 1M context, and 64K maximum output). Each of the 105 tasks runs in an isolated Docker container using the resources declared in its Task Card. The default timeout is 4 hours, with task-specific limits taking precedence (up to 8 hours). Tool Search is disabled, and results are scored by the official ALE evaluators.
  • Toolathlon Verified: We obtain all results via the official evaluation service and report pass@1 averaged over 3 independent runs.
  • AutomationBench: We evaluate on AutomationBench v1.0.6, incorporating the fix for the null-type handling issue introduced in PR #13.
  • GDPval-AA v2: Models are evaluated by Artificial Analysis.
  • CyberGym: We evaluate GLM-5.3 in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0, top_p=1.0, max_new_tokens=128000). All evaluations are under unlimited timeout per task and results are single-run Pass@1 over 1,507 tasks. To simulate real-world usage scenarios, we place the agent inside the task container. We also remove all Git-related information and apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • ExploitGym: We evaluate GLM-5.3, Kimi-K3 and Qwen3.8 Max in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0, top_p=1.0, max_new_tokens=128000). The reported results are single-run Pass@1 on 869 tasks under two timeout budgets: 2 hours and 6 hours, which are calculated as the API inference time rescaled by per-model tokens per second rate (per-model TPS sourced from Artificial Analysis; that is, we rescale GLM-5.3's results by 115 TPS, Kimi K3's results by 40 TPS and Qwen3.8 Max's results by 47 TPS), plus the non-API overhead. We also apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • ExploitBench: We evaluate GLM-5.3 in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0, top_p=1.0, max_new_tokens=128000). Following the official evaluation settings, we limit the maximum number of interaction rounds between the agent and the environment to 300, and compute the average coverage score over all 41 tasks across 3 revisions. The coverage result of a task is determined by taking the union of capabilities achieved across all revisions, and the average score is obtained by averaging the results. We also apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • FrontierSWE: The evaluation was conducted by Proximal with 1M context length, max effort level, and 128K maximum output tokens. Dominance score reported as of 2026/08/14.
  • PostTrainBench: We evaluate GLM-5.3 using Claude Code 2.1.207 with max effort level, temperature = 1.0, top_p = 1.0, max_new_tokens = 128000, and a 1M-token context window. We report the weighted average over 3 runs. Runs that fail to produce a score fall back to the official zero-shot base-model baseline score. For checks intended to prevent the use of third-party APIs, we removed the original pattern-matching-based checks, as they produced false positives when a local vLLM endpoint was accessed through the OpenAI SDK. Instead, we use an LLM agent to inspect solutions for external API usage.
  • SWE-Marathon: We evaluate GLM-5.3 using Claude Code 2.1.207 with maximum effort level, temperature = 1.0, top_p = 0.95, max_new_tokens = 128000, and a 1M-token context window. For strip-clone, the original anti-cheat checks used overly broad import detection that could reject valid implementations. We removed the affected checks and performed llm-based inspection instead to avoid false positiv

(section continues in the model card)

Note (reasoning_effort, clear_thinking)

Note

  • GLM-5.3 supports controlling the thinking budget through the reasoning_effort parameter, which accepts three levels: low, high, and max. It defaults to max if not passed (or if set to any other value). To use low or high, pass them explicitly. For benchmark and leaderboard reproduction, keep the default max.
  • In the chat template for GLM-5.3, clear_thinking defaults to false if not passed. For chat scenarios, explicitly pass clear_thinking=true.

Serve GLM-5.3 Locally (SGLang, vLLM, Ascend NPU...)

Serve GLM-5.3 Locally

GLM-5.3 supports deployment with the following frameworks. Feel free to try them out:

Benchmark (vs GLM-5.2, Kimi K3, DeepSeek-V4, GPT-5.6 etc.)

Benchmark

Benchmark GLM-5.3 GLM-5.2 Kimi K3 DeepSeek-V4 Pro-0813 Qwen3.8-Max Opus 4.8 Fable 5 (w/ fallback) GPT-5.6 Sol
Terminal Bench 2.1 88.2 81.0 88.3 87.9 86.6 85.0 88.0 88.8
Terminal Bench 3.0 28.3 4.6 17.4 – – 21.1 33.7 34.6
DeepSWE (v1.1) 66.9 46.2 67.5 62.7 56.6 58.0 69.7 72.7
NL2Repo 58.0 48.9 58.0 61.1 55.9 69.7 – –
ProgramBench (Almost Solved) 19.0 9.5 17.5 – 10.5 15.5 33.0 23.0
FrontierSWE 78.1 67.5 – – – 66.5 88.2 –
SWE-Marathon (v1.1) 42.5 19.4 48.1 – – 48.8 33.1 42.5
PostTrainBench 39.8 31.7 32.0 – – 32.9 41.8 36.2
CyberGym 84.5 77.2 80.0 83.3 78.5 78.1 83.8 83.6
ExploitGym (2h / 6h) 105 / 130 29 / 39 36 / 70 – 14 / 26 80 / 120 181 / 247 216 / 293
ExploitBench 54.4 24.4 32.2 – 28.8 40.0 78.0 76.5
Toolathlon Verified 73.0 59.9 76.5 74.1 72.5 76.2 74.7 74.9
AutomationBench (v1.0.6) 48.2 26.2 46.7 43.2 39.8 41.0 46.2 45.8
Agents' Last Exam (ALE-CLI) 28.5 23.8 27.6 25.7 27.0 25.7 23.8 28.6
HLE w/ Tools 62.5 54.7 59.8 60.0 56.2 57.9 63.9 64.5
GDPval-AA v2 1769 1508 1682 1590 1739 1588 1743 1730

Introduction (coding + emergent cyber capability)

GLM-5.3

GLM-5.3 uses the same base model as GLM-5.2 — every gain comes from post-training. Compared with GLM-5.2, it is much better at complex coding and long-horizon tasks:

  • Stronger Coding: GLM-5.3 is the most capable open-weights model for coding, with a 50% improvement over GLM-5.2 on our in-house Z.ai Code Bench. It also achieve open-source SOTA on public benchmarks including Terminal Bench 3.0 and Agents' Last Exam.
  • Emergent Cyber Capability: As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks.

bench53

Architecture

Decoder Block input Embedding vocab 155K · d 6144 Full Attention 64 heads · dₕ 192 ×78 MoE FFN 256 experts · top-8 · +1 shared · dᴻ 2048 MTP Head ×1 speculative layer Final Norm LM Head vocab 155K output
Attention
Sparse Attention
MoE
256 experts · top-8 per token
Layers
78
Hidden size
6144
Context
1M tokens
Parameters
753329.9M
Active params
43046.5M

Source: Hugging Face config.json · GlmMoeDsaForCausalLM · model repo

Type: Sparse MoE Transformer with DeepSeek-style Sparse Attention (DSA) lightning indexer
Attention: MLA (q_lora_rank=2048, kv_lora_rank=512, qk_nope 192, qk_rope 64, v 256, 64 heads) + IndexShare lightning indexer (32 heads x 128-dim, index_topk=2048, re-index every 4 layers)
Decoder: Transformer decoder, 78 layers (3 dense FFN + 75 sparse MoE), SwiGLU
MoE: yes (256 experts)
Routing: sigmoid scoring (noaux_tc), top-8 + 1 shared expert, routed_scaling_factor 2.5
Layers 78
Routed experts 256
Experts per token 8
Shared experts 1
Attention heads 64
KV heads 64
Hidden size 6144
Vocabulary 155K
Expert FFN dim 2048
Dense FFN dim 12K
MTP layers 1
RoPE θ 8M
Class GlmMoeDsaForCausalLM (model_type glm_moe_dsa)
First K Dense Replace 3
Hidden Act silu
Index Head Dim 128
Index N Heads 32
Index Topk 2048
Index Topk Freq 4
Kv Lora Rank 512
Max positions 1M
Moe Layer Freq 1
Q Lora Rank 2048
Qk Nope Head Dim 192
Qk Rope Head Dim 64
Quantization FP8 e4m3 dynamic (128x128 block), BF16 attention/embeddings
V Head Dim 256

Training Pipeline

  1. 2
    rl

    Agentic post-training (coding + long-horizon/cyber RL)

    GLM-5.3 reuses the GLM-5.2 base model; all capability gains come from scaled post-training. Key outcomes: strongest open-weights coding model (+50% over GLM-5.2 on in-house Z.ai Code Bench; open-source SOTA on Terminal-Bench 3.0 and Agents' Last Exam), emergent cyber capability (SOTA on CyberGym vulnerability discovery; more than doubles GLM-5.2 on exploitation benchmarks ExploitGym/ExploitBench). Supports reasoning_effort low/high/max (default max) and clear_thinking.

Training & Evaluation Datasets

NameRoleSizeModalitiesCollection
Post-training corpus (coding, long-horizon agentic, cyber) rl — —

Trend Analysis

24h Change

+42.6%

Current

94,403

huggingface

likes

+3.8%

huggingface

downloads_all_time

+42.6%

huggingface

followers

+0.4%

ollama

downloads

+16.9%

View raw metric history →

Usage & Social Metrics

SourceMetricValuePeriodRecorded
ollama downloads 24,900 pulls daily 01.09.2026
huggingface downloads_all_time 94,403 daily 01.09.2026
huggingface followers 20,001 daily 01.09.2026
huggingface likes 1,466 daily 01.09.2026
huggingface downloads 94,403 daily 01.09.2026
ollama downloads 21,300 pulls daily 31.08.2026
huggingface downloads_all_time 66,195 daily 31.08.2026
huggingface followers 19,927 daily 31.08.2026
huggingface likes 1,412 daily 31.08.2026
huggingface downloads 66,195 daily 31.08.2026
ollama downloads 14,700 pulls daily 30.08.2026
huggingface downloads_all_time 50,116 daily 30.08.2026
huggingface followers 19,819 daily 30.08.2026
huggingface likes 1,334 daily 30.08.2026
huggingface downloads 50,116 daily 30.08.2026
ollama downloads 10,100 pulls daily 29.08.2026
huggingface followers 19,739 daily 29.08.2026
huggingface likes 1,265 daily 29.08.2026
huggingface downloads 8,804 daily 29.08.2026

View full metric history →

Related Models