In brief: Z.ai disabled parts of ZCode after users reported undisclosed uploads of local repositories. The company apologised, says stored data was deleted, and released the client, backend services and runtime under Apache 2.0. The evidence also shows why packaging attempts must be distinguished from completed uploads.
Confirmed: one small upload completed
Developer Feng Ruohang examined ZCode 3.12.3 on macOS. Default-enabled codebase indexing created workspace snapshots. The server supplied a public key and temporary Alibaba Cloud OSS credentials; the client packaged and encrypted the files. It recorded at least one small public repository snapshot as accepted.
A larger finding must not be conflated with that result. A 313 MB encrypted archive from a commercial workspace triggered 564 upload attempts but did not leave the machine. A separate repository with 538 files, compressing to roughly 15 KB, was transferred. The pipeline could upload data, but the widely cited 313 MB is not a confirmed transfer.
Snapshots could include the .git directory, placing commit history, deleted files and old secrets in an archive even when absent from the current tree. Encryption protects the transfer from outsiders; it does not prevent the operator holding the private key from processing the contents.
Remediation and the remaining evidence gap
Z.ai told Reuters that the affected features were disabled and the vulnerability patched. An independent review reportedly confirmed deletion of uploaded user data. The public repository now includes clients, backend services and the agent runtime. However, the official September 22 entry for version 3.14.3 lists functional and stability changes rather than documenting the security fix in detail.
Pandorex Analysis
Open source improves auditability, but does not prove deletion of historical cloud copies or reveal the earlier server configuration. The enterprise issue is the consent and data-egress boundary: a local development environment should not send complete repositories to third-party infrastructure by default. Affected teams should update or remove ZCode, review local state and network logs, and rotate credentials that may have existed in Git history. Without logs or server evidence, the exact contents of each completed upload cannot be reconstructed.
