Z.ai Disables Coding Assistant Features After Unauthorized Code Uploads to Alibaba Cloud
Chinese AI company Z.ai recently disabled key features of its ZCode coding assistant following revelations that a default setting was silently transmitting users’ local code repositories including full .git histories, LFS assets, and configuration files to Alibaba Cloud’s OSS storage in China without explicit consent. The incident, first uncovered by independent Chinese blogger Ferstar, exposed enterprise concerns over how AI tools handle sensitive intellectual property.
The flaw stemmed from a default-enabled workflow that packaged and encrypted entire development environments before uploading them to Alibaba’s cloud infrastructure. While Z.ai confirmed the data was not used for model training and has since been deleted, the breach highlighted risks tied to broad filesystem access and unchecked network permissions in AI-assisted development tools.
Security experts, including Semgrep’s Cris Thomas and Katie Paxton-Fear, emphasized that the issue was less about AI itself and more about poor security architecture. Thomas noted that such tools should operate under minimum default permissions, with clear disclosures about data handling. Paxton-Fear added that enterprises must rigorously vet AI deployments, given the high stakes of exposing proprietary code.
Z.ai responded by disabling the upload mechanism, removing the associated cloud storage, and releasing an updated client (v3.14.0). The company also engaged third-party auditors, including NSFOCUS and the China Academy of Information and Communications Technology (CAICT), to assess its security practices. In a statement, Z.ai thanked community developers for identifying the flaw and committed to improving its vulnerability reporting process.
The incident underscores broader challenges in AI tool governance, particularly around transparency, data sovereignty, and unintended system behaviors issues that have drawn scrutiny from industry watchdogs and regulators alike.
Z.ai TPRM report: https://www.rankiteo.com/company/zdotai
Alibaba Cloud TPRM report: https://www.rankiteo.com/company/alibabacloudglobal
"id": "alizdo1790094428",
"linkid": "alibabacloudglobal, zdotai",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of ZCode coding assistant',
'industry': 'Technology/AI',
'location': 'China',
'name': 'Z.ai',
'type': 'AI Company'}],
'attack_vector': 'Misconfiguration',
'customer_advisories': 'Public statement and updated client release (v3.14.0)',
'data_breach': {'data_encryption': 'Yes (packaged and encrypted before '
'upload)',
'data_exfiltration': 'Uploaded to Alibaba Cloud’s OSS storage '
'in China',
'file_types_exposed': ['.git histories',
'LFS assets',
'configuration files'],
'sensitivity_of_data': 'High (proprietary code, intellectual '
'property)',
'type_of_data_compromised': 'Code repositories, `.git` '
'histories, LFS assets, '
'configuration files'},
'description': 'Chinese AI company Z.ai recently disabled key features of its '
'ZCode coding assistant following revelations that a default '
'setting was silently transmitting users’ local code '
'repositories including full `.git` histories, LFS assets, and '
'configuration files to Alibaba Cloud’s OSS storage in China '
'without explicit consent. The flaw exposed enterprise '
'concerns over how AI tools handle sensitive intellectual '
'property.',
'impact': {'brand_reputation_impact': 'Enterprise concerns over AI tool '
'governance and data sovereignty',
'data_compromised': 'Local code repositories, `.git` histories, '
'LFS assets, and configuration files',
'operational_impact': 'Disabled key features of ZCode coding '
'assistant',
'systems_affected': 'ZCode coding assistant'},
'investigation_status': 'Completed (third-party audits conducted)',
'lessons_learned': 'AI tools must operate under minimum default permissions '
'with clear disclosures about data handling. Enterprises '
'must rigorously vet AI deployments due to risks of '
'exposing proprietary code.',
'post_incident_analysis': {'corrective_actions': 'Disabled upload mechanism, '
'removed cloud storage, '
'released updated client, '
'engaged third-party '
'auditors, improved '
'vulnerability reporting '
'process',
'root_causes': 'Poor security architecture, broad '
'filesystem access, unchecked '
'network permissions, lack of '
'explicit user consent'},
'recommendations': ['Implement minimum default permissions for AI tools',
'Provide clear disclosures about data handling practices',
'Conduct rigorous security vetting of AI deployments',
'Improve transparency and vulnerability reporting '
'processes'],
'references': [{'source': 'Ferstar (independent Chinese blogger)'},
{'source': 'Semgrep (Cris Thomas)'},
{'source': 'Katie Paxton-Fear'}],
'response': {'communication_strategy': 'Public statement thanking community '
'developers, commitment to improving '
'security practices',
'containment_measures': 'Disabled the upload mechanism, removed '
'associated cloud storage',
'remediation_measures': 'Released updated client (v3.14.0), '
'improved vulnerability reporting '
'process',
'third_party_assistance': 'NSFOCUS, China Academy of Information '
'and Communications Technology '
'(CAICT)'},
'title': 'Z.ai Disables Coding Assistant Features After Unauthorized Code '
'Uploads to Alibaba Cloud',
'type': 'Data Exposure',
'vulnerability_exploited': 'Default-enabled workflow with broad filesystem '
'access and unchecked network permissions'}