ZCode uploaded workspace snapshots to Alibaba Cloud

Zhipu's ZCode team apologised on X at 09:23 SGT on 21 September 2026. The statement answered community reports that the ZCode desktop coding agent had uploaded users' code.

The first public report came from developer ferstar on 18 September. His write-up says ZCode packaged whole workspaces while users were logged in. The packages included .git history, the LFS cache and reflogs. The client encrypted each package with an RSA public key sent by the server and uploaded it to Aliyun OSS.

Ferstar says a 313 MB commercial project stalled in a pending state and never finished uploading. A small public repository of 538 files did upload, and the server accepted it. He says turning off the relevant settings in version 3.12.3 left the packaging active.

Zhipu's ZCode changelog lists version 3.14.0 on 19 September. Its bug fixes include "Fixed an issue with abnormal uploads in the repository wiki".

Zhipu also posted a first statement in its user community on 18 September. That post sits in a closed group, and Zhipu has published no public copy.

Zhipu's ZCode team owns the fix and the statement

ZCode is the AI coding app from Zhipu, which trades internationally as Z.ai. The zcode.z.ai site lists the zcode_ai account on X as the product's official channel.

The 21 September statement makes four commitments:

  • It apologises to all users.
  • It says Zhipu has open-sourced ZCode on GitHub "placing the code under community scrutiny".
  • It promises an ongoing process for reporting security bugs, with rewards based on severity.
  • It says "no such data is retained and that it has never been used for model training".

The statement cites two outside assessments. The China Academy of Information and Communications Technology (CAICT) confirmed that the zcode-prod Alibaba Cloud OSS bucket "is in a zero-data state". NSFOCUS confirmed that all objects in the bucket, and the bucket itself, were deleted.

Version 3.14.0 removes Repo Wiki and snapshot uploads

According to the statement, version 3.14.0 removed the Repo Wiki feature. It also disabled the workflow that generated and uploaded local repository snapshots.

NSFOCUS found "no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally". That finding covers the 3.14.0 client.

The GitHub repository appeared at 20:01 SGT on 20 September. It uses the Apache 2.0 licence and has issues switched off. It holds three commits: an initial commit, an "open source" commit and a version 3.14.3 update on 23 September. The repository carries no history from before the fix.

Ferstar reviewed the open code on 21 and 23 September. He found no trace of the snapshot upload endpoint or the upload encryption code. He also says the open repository has no commit that shows how the upload code was removed.

The audit reports and upload scope stay unpublished

Zhipu has published only a summary of the CAICT and NSFOCUS findings. The statement says "The full security assessment report will be released soon." No date appears. As of 28 September, we found no report on ZCode's X account, its changelog or its GitHub repository.

The findings cover the bucket state after the fix.

New upload claims surfaced on 25 September. A user post on X shared a screenshot and claimed that versions after 3.14 still uploaded code indexes. ZCode replied on X at 22:01 SGT that day. It said the IP address in the screenshot is not a ZCode service endpoint. It said version 3.14.0 removed the feature, and it asked for full logs to check further. The reply is in Chinese, and the translation is ours. No one has published logs that settle the claim. Neither summary says how many users uploaded code, how long the data stayed in the bucket or who could decrypt it.

The repository NOTICE file describes several defaults that affect data handling. The file is in Chinese, and the translations below are ours:

  • The shared agent execution adapter provides no default operating system sandbox.
  • The standalone CLI uses the "yolo" mode for non-interactive runs with --prompt when the user sets no mode.
  • The shared agent writes model input and output logs to local disk by default in development and production.
  • The CLI encrypts its credential file, and the default key can derive from local machine information.
  • Requests to two official Coding Plan endpoints are forwarded to the ZCode gateway, with their authentication headers.
  • Memory is on by default in the CLI and off by default in the desktop app.

ZCode users should update and check old workspaces

  1. Update ZCode to version 3.14.0 or later. The changelog lists 3.14.1 and 3.14.3 on 22 September.
  2. List the repositories you opened in ZCode while logged in before 19 September. Treat any secrets in their .git history as exposed and rotate them.
  3. Ask Zhipu in writing whether data from your account reached the zcode-prod bucket and when it was deleted.
  4. Read the NOTICE file before you run the CLI in scripts. Set --mode explicitly so that non-interactive runs avoid the yolo default.
  5. Security teams should watch for the full CAICT and NSFOCUS reports and compare them with the open code.