Z.ai's ZCode coding assistant silently uploaded users' local code repositories to Alibaba Cloud servers
A default-enabled workflow in Z.ai's ZCode coding assistant packaged users' local code repositories, including git history and app configs, and uploaded them to Alibaba Cloud object storage in China without user consent. An independent Chinese blogger found the behaviour after tracing abnormal disk usage to ZCode's background processes. Z.ai apologised, disabled the upload workflow, deleted the associated cloud storage and shipped changes in ZCode v3.14.0. It also asked CAICT and NSFOCUS to run security assessments and said the data was never used for model training.
Disclosed September 22, 2026
Who is exposed
Developers and enterprises that ran the ZCode client while logged in. Their full workspaces, which could include proprietary code and embedded credentials, may have been uploaded to Alibaba Cloud storage in China.
What to do
Check whether ZCode was used on company machines, update to v3.14.0 or remove it, and rotate any credentials stored in affected repositories. Before deploying AI coding tools, vet what data they send, where it goes and how long it is kept, and restrict their filesystem and network permissions.
Rules it touches
Data protection and consent requirements for transferring user data, cross-border data transfer rules, and trade-secret and confidentiality obligations for proprietary source code.
Who was involved
As named in the sources. Parties are alleged unless a source reports a finding or an admission.
- Affected partiesEnterprises and developers using ZCode
“raising fresh concerns for enterprises over how AI tools handle sensitive source code”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk - Destination of uploaded dataAlibaba Cloud servers in China
“Alibaba Cloud servers in China without their consent”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk - Developer of the coding assistantZ.ai (ZCode)
“Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Other facts
- Company claim on training useData never used for model training
“has never been used for model training”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk - DiscoveryFound by an independent Chinese blogger
“The issue first surfaced through a technical investigation by an independent Chinese blogger”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk - Remediated client versionZCode v3.14.0
“implemented changes in the ZCode v3.14.0 client”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk - Data deletion confirmationNSFOCUS confirmed the bucket and its data were deleted
“NSFOCUS confirmed that all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted”
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk

