Cantina Security, working with Yeta Labs, has released apex-flash-1, an open-weights model designed specifically for vulnerability research. It is a reinforcement learning fine-tune of Z.ai's GLM-5.3-Flash and is available on Hugging Face under the MIT license.

In testing, apex-flash-1 solved 40 of 60 held-out bug tasks, a result that suggests open-weights models can meaningfully contribute to security research. The benchmark tasks were not part of the model's training, so the performance reflects generalization rather than memorization.

Because the model is MIT-licensed and open-weights, it can be deployed by a wide range of users. The release positions apex-flash-1 as a practical option for teams that want security research capabilities without relying on closed, proprietary systems.