Urgent.News

What's breaking now, across thousands of outlets.

AI

Z.ai says sorry for slurping up your code, open sources ZCode

China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws

Z.ai says sorry for slurping up your code, open sources ZCode

Chinese AI company Z.ai has issued an apology after its code-generation assistant, ZCode, was found to be automatically uploading users' workspaces to Alibaba Cloud storage without their consent. This behavior closely resembles the controversy that Elon Musk's xAI faced in July regarding the same issue. ZCode packaged and git-encrypted entire user workspaces, including complete project histories, and sent them to the cloud.

The private key used to decrypt the data was held only by the company's server, preventing users from accessing or deleting the files. Z.ai's researcher Ferstar discovered the issue, stating there were no options for users to disable the behavior or any disclosure in ZCode's privacy policy. The problem stemmed from the tool's Repository Index functionality, which automatically uploaded files after Repo Wiki generated pages in the cloud.

ZCode has apologized for the security issues and confirmed that the uploaded data was never used to train its models. The company stated that it will establish an ongoing product security vulnerability reporting and response process and welcomes continued scrutiny from the community. ZCode has already removed the Repo Wiki feature and open sourced the entire project on GitHub for community review.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in AI

llm-typesafe 0.1a0

Release: llm-typesafe 0.1a0 I built this new plugin for LLM to add support for TypeSafe AI's new Jev model . Install it like this: llm install llm-typesafe Then set an API key ( get one here , the…

More from Tuesday 22 September →