{"slug": "z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload", "title": "Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk", "summary": "Z.ai disabled the repository-snapshot upload workflow in its ZCode coding assistant and shipped the fix in ZCode v3.14.0 after an independent Chinese blogger, Ferstar, found that a default-enabled setting packaged users' entire local workspaces — including full .git history, LFS asset caches, reflogs and global app configs — and uploaded them to Alibaba Cloud OSS (Aliyun) without consent. Z.ai said it deleted the zcode-prod Alibaba Cloud OSS bucket and all data objects, removed the Repo Wiki entry point and its generation workflow, and engaged the China Academy of Information and Communications Technology (CAICT) and NSFOCUS for security assessments; NSFOCUS confirmed the bucket and its objects were deleted. Z.ai said the data was never used for model training, while Semgrep security advocate Cris Thomas said the incident is \"an old-fashioned security architecture problem\" rather than an AI model problem.", "body_md": "Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code.\n\nThe company apologised and said it had “completed the necessary remediation,” disabling the workflow responsible for generating and uploading local repository snapshots in its ZCode client. It has [removed the feature](https://x.com/zcode_ai/status/2101844704933621971) from the latest release and [opened up its codebase for public scrutiny](https://github.com/zai-org/ZCode), it said in a post on X.\n\nThe issue first surfaced through a technical investigation by an independent Chinese blogger, who described discovering abnormal disk usage and tracing it to ZCode’s background processes.\n\n“Whenever you are logged in, ZCode silently packages your entire workspace — complete .git history, LFS asset cache, reflogs, and global app configs — encrypts it, and uploads it directly to Aliyun OSS,” Chinese blogger Ferstar wrote in a blog post detailing their investigation, [according to a machine translation they provided](https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/).\n\nAccording to the blogger, the ZCode coding assistant was not just accessing active files but capturing the broader development environment, effectively creating a pipeline from local systems to cloud storage.\n\nThe blogger said the data was uploaded to Alibaba Cloud object storage, raising concerns about how enterprise codebases including proprietary logic and embedded credentials could be handled once they left local environments.\n\nZ.ai acknowledged the issue, thanking community developers for identifying it and committing to an ongoing vulnerability reporting and response process.\n\nAs part of its response, the company said it had disabled the repository upload mechanism, deleted associated cloud storage infrastructure, and implemented changes in the ZCode v3.14.0 client.\n\nZ.ai also asked the China Academy of Information and Communications Technology (CAICT) and NSFOCUS to conduct security assessments.\n\n“NSFOCUS confirmed that all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted,” Z.ai added in the post. “The Repo Wiki entry point and the associated generation workflow have been removed, and no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally was identified.”\n\nThe company also said that no such data is retained and “has never been used for model training,” addressing concerns over downstream use of uploaded code.\n\nIn the Z.ai case, Ferstar’s findings showed that a default-enabled workflow could package and transmit entire repositories from local environments to cloud infrastructure without explicit user action, behavior the company later addressed in its remediation update.\n\n“This isn’t really an AI model problem, it’s an old-fashioned security architecture problem,” said Cris Thomas, security advocate at Semgrep. If a coding assistant can “package up my entire repository and ship it somewhere I didn’t explicitly approve,” he said, the issue lies in how access and permissions are enforced.\n\n“Giving an AI access to proprietary source code should require clear disclosure about what leaves the machine, where it goes, how long it’s retained and who can access it, with the minimum permissions turned on by default, not the maximum,” he said.\n\nThe risk extends beyond cloud-based deployments. Systems running locally can still expose sensitive data if they are granted broad filesystem access and unrestricted network connectivity, he added.\n\nSemgrep staff security advocate Katie Paxton-Fear said, “Given how much intellectual property is in code, it’s not surprising that people are worried about it being sent to a third-party cloud provider,” adding that organizations need to more rigorously vet the AI tools they deploy.\n\nRecent [disclosures](https://www.csoonline.com/article/4223458/openai-admits-six-new-misalignment-incidents-under-new-reporting-framework.html) from OpenAI on model misalignment and reporting frameworks have also pointed to instances of unexpected system behavior, highlighting how AI systems can operate in ways not fully anticipated during deployment.", "url": "https://wpnews.pro/news/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload", "canonical_source": "https://www.infoworld.com/article/4225022/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk.html", "published_at": "2026-09-22 14:53:57+00:00", "updated_at": "2026-09-22 15:24:38.814165+00:00", "lang": "en", "topics": ["ai-tools", "ai-products", "ai-safety", "ai-policy"], "entities": ["Z.ai", "ZCode", "Alibaba Cloud", "Ferstar", "China Academy of Information and Communications Technology", "NSFOCUS", "Semgrep", "Cris Thomas"], "alternates": {"html": "https://wpnews.pro/news/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload", "markdown": "https://wpnews.pro/news/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload.md", "text": "https://wpnews.pro/news/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload.txt", "jsonld": "https://wpnews.pro/news/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload.jsonld"}}