# OpenVuln

> Source: https://aiwiki.ai/wiki/openvuln
> Updated: 2026-10-02
> Fact-checked: 2026-10-02
> Categories: AI Tools & Products, AI in Cybersecurity, Developer Tools
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "OpenVuln." aiwiki.ai, 2 Oct 2026. https://aiwiki.ai/wiki/openvuln
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

**OpenVuln** is a vulnerability-discovery service from [Z.ai](https://aiwiki.ai/wiki/zhipu_ai) for public software repositories. It uses GLM models to help maintainers investigate security flaws, while separating public aggregate statistics from restricted finding details. Its public interface is available through the company's [Hugging Face](https://aiwiki.ai/wiki/hugging_face) Space.[1][2]

On September 30, 2026, Zixuan Li reported that [GLM-5.3](https://aiwiki.ai/wiki/glm_5_3) had identified 4,249 potential vulnerabilities across 389 open-source projects through the continuing service. Li described OpenVuln as free and said findings were sent privately to maintainers. The wording identifies candidate findings, not 4,249 independently confirmed vulnerabilities, public CVEs, or completed fixes.[3]

## Repository scanning and access

The hosted interface accepts a public repository and offers an option to select a specific version. In October 2026, it labeled submissions as restricted to repository maintainers, warned that a submission might need manual review, and estimated that a full scan usually takes at least 12 hours. That estimate describes the service's expected duration rather than a completion guarantee.[1]

The public project index lists repositories with their language, last scan, finding count, and severity information. The homepage also displays aggregate repository and finding totals, a severity breakdown, and current scanning activity.[1]

The linked source repository describes a queue connected to the external VulnHunter scanning engine. It documents GitHub OAuth verification of repository permissions, with administrator or maintainer access used to establish ownership privileges. Detailed reports remain private to verified maintainers until disclosure. The implementation provides owner-controlled batch disclosure and report exports, including Markdown and JSON summaries.[2]

This distinction between identifying an issue and publishing it is part of coordinated vulnerability disclosure. CERT/CC describes coordination as work among affected stakeholders to analyze a vulnerability, address it, and provide accurate mitigation or repair information to the public. Private reporting is one stage of that process; it does not by itself show that an issue has been confirmed or fixed.[4]

## Public implementation

The Hugging Face repository describes the Space as a public frontend. It packages a Vite application in a Docker-based Space, serves the application with nginx, and allows its API origin to be configured separately. The default origin is the hosted OpenVuln service. Hosting the interface on Hugging Face therefore does not mean the Space contains the scanning engine or model weights.[5]

The linked Clouditera repository calls its implementation a prototype. Its published components include a React interface, a Hono-based service, shared API types, a database-backed scan queue, and a client for VulnHunter. The repository uses the Apache License 2.0. That license describes the published OpenVuln code; it should not be read as a license for a separately supplied GLM model or as evidence that the external engine is included.[2]

## Reported findings

The service publishes activity counts rather than a standardized [benchmark](https://aiwiki.ai/wiki/benchmark) score. Two dated observations illustrate the distinction between a reported milestone and a changing dashboard:

| Observation | Projects or repositories | Findings | Meaning |
|---|---:|---:|---|
| Zixuan Li's September 30, 2026 update | 389 projects | 4,249 potential vulnerabilities | A first-party report about the ongoing service.[3] |
| Public OpenVuln interface observed October 2, 2026 | 403 repositories scanned | 4,358 findings discovered | A dashboard snapshot, not an independently audited count of confirmed flaws.[1] |

The September update does not provide a per-finding validation record, false-positive rate, or number of completed fixes. Those quantities cannot be calculated from its project and candidate-finding totals.[3]

Z.ai's earlier GLM-5.3 announcement describes a broader security program that began during GLM-5.2 development and involved several security teams. It reported 2,436 vulnerabilities across 269 projects after expert review, screening, and deduplication. That earlier program total is not a measurement of GLM-5.3 alone, and it has a different stated scope from Li's later OpenVuln update. The launch article also describes a disclosure ledger that distinguished public issues from findings still undergoing disclosure.[6]

By October 2, the separate Z.ai Security Disclosure Ledger site displayed a notice directing future publication of model-discovered vulnerabilities to CNVD, CNNVD, and NVDB. It said the site would no longer display individual vulnerability details. The notice did not announce that OpenVuln scanning had ended.[7]

## Relation to cybersecurity evaluations

OpenVuln's operational counts and evaluations of its associated models answer different questions. A scan tally describes activity on submitted or selected projects. A benchmark measures performance on a defined collection of tasks under specified conditions.

For example, the CyberGym research paper describes 1,507 historical vulnerabilities and a primary task in which an agent receives a vulnerability description and the corresponding codebase, then produces a test that reproduces the flaw. Proposed tests are checked against program versions before and after the fix. The authors distinguish this reproducible evaluation from open-ended discovery, whose search space makes measurement more difficult. A result on that task is not a count of newly discovered OpenVuln findings.[8]

NIST's Center for AI Standards and Innovation separately evaluated GLM-5.3 on four vulnerability-discovery and exploit-development benchmarks in September 2026. CAISI assessed it as the strongest released open-weight model it had evaluated for cyber capabilities at that time, while finding it substantially behind the evaluated U.S. frontier models. Its tests used an agent harness, prescribed reasoning settings, and task limits. These are results for the evaluated model configurations, not an independent validation of OpenVuln's repository totals, reporting accuracy, or remediation outcomes.[9]

## See also

- [AI in Cybersecurity](https://aiwiki.ai/wiki/ai_in_cybersecurity)
- [AI Agents](https://aiwiki.ai/wiki/ai_agents)

## References

1. Z.ai. [OpenVuln, public Hugging Face Space](https://huggingface.co/spaces/zai-org/OpenVuln). Interface observed October 2, 2026.
2. Clouditera. [OpenVuln source repository and README](https://github.com/Clouditera/OpenVuln). Accessed October 2, 2026.
3. Zixuan Li. [OpenVuln project and potential-vulnerability update](https://x.com/ZixuanLi_/status/2105120154329977240). September 30, 2026.
4. CERT Coordination Center. [Vulnerability Disclosure Guidance](https://www.kb.cert.org/vuls/guidance/). Accessed October 2, 2026.
5. Z.ai. [OpenVuln Space README](https://huggingface.co/spaces/zai-org/OpenVuln/blob/main/README.md). Accessed October 2, 2026.
6. Z.ai. [GLM-5.3 announcement](https://z.ai/blog/glm-5.3). August 14, 2026.
7. Z.ai. [Security Disclosure Ledger](https://cvd.z.ai/). Migration notice observed October 2, 2026.
8. Zhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai, Jialin Zhang, and Dawn Song. [CyberGym: Evaluating AI Agents' Cybersecurity Capabilities with Real-World Vulnerabilities at Scale](https://arxiv.org/abs/2506.02548v1). June 3, 2025.
9. National Institute of Standards and Technology. [CAISI's Assessment of Z.ai's GLM-5.3 Cyber Capabilities](https://www.nist.gov/news-events/news/2026/09/caisis-assessment-zais-glm-53-cyber-capabilities). September 17, 2026.

