{"id":9556,"date":"2026-09-22T14:56:08","date_gmt":"2026-09-22T14:56:08","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9556"},"modified":"2026-09-22T14:56:08","modified_gmt":"2026-09-22T14:56:08","slug":"z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9556","title":{"rendered":"Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users\u2019 local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code.<\/p>\n<p class=\"wp-block-paragraph\">The company apologised and said it had \u201ccompleted the necessary remediation,\u201d disabling the workflow responsible for generating and uploading local repository snapshots in its ZCode client. It has <a href=\"https:\/\/x.com\/zcode_ai\/status\/2101844704933621971\" target=\"_blank\" rel=\"noopener\">removed the feature<\/a> from the latest release and <a href=\"https:\/\/github.com\/zai-org\/ZCode\" target=\"_blank\" rel=\"noopener\">opened up its codebase for public scrutiny<\/a>, it said in a post on X.<\/p>\n<h2 class=\"wp-block-heading\">Community findings exposed full repository transfer<\/h2>\n<p class=\"wp-block-paragraph\">The issue first surfaced through a technical investigation by an independent Chinese blogger, who described discovering abnormal disk usage and tracing it to ZCode\u2019s background processes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhenever you are logged in, ZCode silently packages your entire workspace \u2014 complete .git history, LFS asset cache, reflogs, and global app configs \u2014 encrypts it, and uploads it directly to Aliyun OSS,\u201d Chinese blogger Ferstar wrote in a blog post detailing their investigation, <a href=\"https:\/\/blog.ferstar.org\/en\/posts\/zcode-silent-workspace-snapshot-upload\/\" target=\"_blank\" rel=\"noopener\">according to a machine translation they provided<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">According to the blogger, the ZCode coding assistant was not just accessing active files but capturing the broader development environment, effectively creating a pipeline from local systems to cloud storage.<\/p>\n<p class=\"wp-block-paragraph\">The blogger said the data was uploaded to Alibaba Cloud object storage, raising concerns about how enterprise codebases including proprietary logic and embedded credentials could be handled once they left local environments.<\/p>\n<p class=\"wp-block-paragraph\">Z.ai acknowledged the issue, thanking community developers for identifying it and committing to an ongoing vulnerability reporting and response process.<\/p>\n<h2 class=\"wp-block-heading\">Remediation, audits, and vendor assurances<\/h2>\n<p class=\"wp-block-paragraph\">As part of its response, the company said it had disabled the repository upload mechanism, deleted associated cloud storage infrastructure, and implemented changes in the ZCode v3.14.0 client.<\/p>\n<p class=\"wp-block-paragraph\">Z.ai also asked the China Academy of Information and Communications Technology (CAICT) and NSFOCUS to conduct security assessments.<\/p>\n<p class=\"wp-block-paragraph\">\u201cNSFOCUS confirmed that all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted,\u201d Z.ai added in the post. \u201cThe Repo Wiki entry point and the associated generation workflow have been removed, and no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally was identified.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The company also said that no such data is retained and \u201chas never been used for model training,\u201d addressing concerns over downstream use of uploaded code.<\/p>\n<h2 class=\"wp-block-heading\">AI assistants blur enterprise data boundaries<\/h2>\n<p class=\"wp-block-paragraph\">In the Z.ai case, Ferstar\u2019s findings showed that a default-enabled workflow could package and transmit entire repositories from local environments to cloud infrastructure without explicit user action, behavior the company later addressed in its remediation update.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis isn\u2019t really an AI model problem, it\u2019s an old-fashioned security architecture problem,\u201d said Cris Thomas, security advocate at Semgrep. If a coding assistant can \u201cpackage up my entire repository and ship it somewhere I didn\u2019t explicitly approve,\u201d he said, the issue lies in how access and permissions are enforced.<\/p>\n<p class=\"wp-block-paragraph\">\u201cGiving an AI access to proprietary source code should require clear disclosure about what leaves the machine, where it goes, how long it\u2019s retained and who can access it, with the minimum permissions turned on by default, not the maximum,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">The risk extends beyond cloud-based deployments. Systems running locally can still expose sensitive data if they are granted broad filesystem access and unrestricted network connectivity, he added.<\/p>\n<p class=\"wp-block-paragraph\">Semgrep staff security advocate Katie Paxton-Fear said, \u201cGiven how much intellectual property is in code, it\u2019s not surprising that people are worried about it being sent to a third-party cloud provider,\u201d adding that organizations need to more rigorously vet the AI tools they deploy.<\/p>\n<p class=\"wp-block-paragraph\">Recent <a href=\"https:\/\/www.csoonline.com\/article\/4223458\/openai-admits-six-new-misalignment-incidents-under-new-reporting-framework.html\">disclosures<\/a> from OpenAI on model misalignment and reporting frameworks have also pointed to instances of unexpected system behavior, highlighting how AI systems can operate in ways not fully anticipated during deployment.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.infoworld.com\/article\/4225022\/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk.html\">InfoWorld<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users\u2019 local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code. The company apologised and said [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9557,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9556","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9556"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9556"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9556\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9557"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}