Pandorex
Security

ZCode Uploaded Repositories Without Clear Consent — Z.ai Opens the Client

Published Pandorex Redaktion·2 min read
—
Illustration: a local code repository is packaged for cloud upload; a barrier stops the path while released source code is inspected under a magnifying glass.
Editorial illustration · Pandorex

In brief: Z.ai disabled parts of ZCode after users reported undisclosed uploads of local repositories. The company apologised, says stored data was deleted, and released the client, backend services and runtime under Apache 2.0. The evidence also shows why packaging attempts must be distinguished from completed uploads.

Confirmed: one small upload completed

Developer Feng Ruohang examined ZCode 3.12.3 on macOS. Default-enabled codebase indexing created workspace snapshots. The server supplied a public key and temporary Alibaba Cloud OSS credentials; the client packaged and encrypted the files. It recorded at least one small public repository snapshot as accepted.

A larger finding must not be conflated with that result. A 313 MB encrypted archive from a commercial workspace triggered 564 upload attempts but did not leave the machine. A separate repository with 538 files, compressing to roughly 15 KB, was transferred. The pipeline could upload data, but the widely cited 313 MB is not a confirmed transfer.

Snapshots could include the .git directory, placing commit history, deleted files and old secrets in an archive even when absent from the current tree. Encryption protects the transfer from outsiders; it does not prevent the operator holding the private key from processing the contents.

Remediation and the remaining evidence gap

Z.ai told Reuters that the affected features were disabled and the vulnerability patched. An independent review reportedly confirmed deletion of uploaded user data. The public repository now includes clients, backend services and the agent runtime. However, the official September 22 entry for version 3.14.3 lists functional and stability changes rather than documenting the security fix in detail.

Pandorex Analysis

Open source improves auditability, but does not prove deletion of historical cloud copies or reveal the earlier server configuration. The enterprise issue is the consent and data-egress boundary: a local development environment should not send complete repositories to third-party infrastructure by default. Affected teams should update or remove ZCode, review local state and network logs, and rotate credentials that may have existed in Git history. Without logs or server evidence, the exact contents of each completed upload cannot be reconstructed.

Sources and references

Sources used for the facts and context in this article.

  1. Z.ai, abgerufen am 24.09.2026: ZCode — offizielles Repositorygithub.com
  2. Z.ai, 22.09.2026: ZCode Changelog, Version 3.14.3zcode.z.ai
  3. Feng Ruohang, 18.09.2026: ZCode Is Silently Uploading Your Codebasevonng.com
  4. Reuters, 21.09.2026, aktualisiert am 22.09.2026: China’s Z.ai disables AI coding assistant features after security issuereuters.com
  5. The Next Web, 22.09.2026: Z.ai open-sources ZCode after repository-upload controversythenextweb.com

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

F5 BIG-IP APM: Exploited OAuth RCE Hits Specific Configurations

Security