Particle.news

Z.ai Disables ZCode Features After Reports It Uploaded Developers' Repositories

The company says it patched a default 'Codebase Indexing' flaw and enabled zero-data retention while users say encrypted uploads prevent independent verification of deletions.

Overview

  • Developers reported that ZCode had uploaded local Git repositories to overseas cloud servers without consent, prompting Z.ai to apologise and disable some assistant features.
  • Z.ai traced the problem to a default 'Codebase Indexing' feature, said it patched the vulnerability, and offered a zero-data retention mode to stop further uploads.
  • The firm open-sourced the ZCode assistant running GLM-5.3 and cited an industry-affiliated think tank and NSFOCUS for an assessment that, it says, found uploaded code was deleted.
  • Users remain sceptical because uploaded files were encrypted with a backend private key controlled only by Z.ai, which blocks independent checks that the files were removed.
  • Chengming Technology retracted its earlier claim of sensitive data exposure and the incident has fed broader policy and trust questions about defaults, disclosure, and auditability for AI developer tools.