🛠 Z.ai Releases OpenVuln — Free AI Vulnerability Reconnaissance for Public GitHub Repositories

The platform became available on August 14: you submit a public GitHub repository, and the AI engine VulnHunter (based on GLM-5.3, according to PlayCISO) scans the code. Aggregated statistics are public, while detailed findings remain with the maintainer until coordinated disclosure.

🌍 According to a Z.ai report, models with GLM-5.2 found 2436 vulnerabilities in 269 open-source projects, of which 1097 were critical/high; 53 were disclosed with CVEs, and 2383 are under embargo. Open source auditing is becoming cheaper, and maintainers receive findings before attackers.

👤 Space zai-org/OpenVuln on Hugging Face, code under Apache-2.0 (Clouditera/OpenVuln). Scanning is done via the openvuln.vulnhunter.pro API, and the frontend is under maintenance. The scanner's accuracy has not yet been independently verified.

Source 1: https://huggingface.co/spaces/zai-org/OpenVuln Source 2: https://playciso.com/blog/openvuln-zai-glm-open-source-vulnerability-scanner