Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
S: Serious, 4/5IncidentConfirmedOECD: Incident

Z.ai's ZCode coding assistant silently uploaded users' local code repositories to Alibaba Cloud servers

A default-enabled workflow in Z.ai's ZCode coding assistant packaged users' local code repositories, including git history and app configs, and uploaded them to Alibaba Cloud object storage in China without user consent. An independent Chinese blogger found the behaviour after tracing abnormal disk usage to ZCode's background processes. Z.ai apologised, disabled the upload workflow, deleted the associated cloud storage and shipped changes in ZCode v3.14.0. It also asked CAICT and NSFOCUS to run security assessments and said the data was never used for model training.

Disclosed September 22, 2026

Who is exposed

Developers and enterprises that ran the ZCode client while logged in. Their full workspaces, which could include proprietary code and embedded credentials, may have been uploaded to Alibaba Cloud storage in China.

What to do

Check whether ZCode was used on company machines, update to v3.14.0 or remove it, and rotate any credentials stored in affected repositories. Before deploying AI coding tools, vet what data they send, where it goes and how long it is kept, and restrict their filesystem and network permissions.

Rules it touches

Data protection and consent requirements for transferring user data, cross-border data transfer rules, and trade-secret and confidentiality obligations for proprietary source code.

Who was involved

As named in the sources. Parties are alleged unless a source reports a finding or an admission.

Other facts

Application Security Isn’t Optional Anymore.