Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Summary
Z.ai's ZCode coding assistant had a critical flaw where a default-enabled setting automatically uploaded users' entire local code repositories (including Git history and configuration files) to Alibaba Cloud servers in China without explicit permission. The company disabled the problematic feature, deleted the uploaded data, and released an updated client (v3.14.0) after independent researchers discovered the issue.
Solution / Mitigation
Z.ai disabled the repository upload mechanism, deleted associated cloud storage infrastructure, implemented changes in ZCode v3.14.0 client, and had independent security firms (NSFOCUS and CAICT) confirm that all data in the Alibaba Cloud storage bucket was deleted and no functional path remains capable of uploading local files. The company removed the Repo Wiki entry point and associated generation workflow.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4225037/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk-2.html
First tracked: September 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%