Zhipu AI Patches ZCode Client After Silent Codebase Uploads Spark Security Backlash.
Zhipu AI (also operating as Z.ai), the Chinese generative artificial intelligence developer behind the GLM model family, has issued an emergency update for its ZCode developer client. The update follows widespread privacy and intellectual property concerns from software engineers who discovered that the tool was automatically exfiltrating entire local source code repositories to foreign cloud infrastructure upon launch.
Automated Indexing Architecture and User Exposure
The code upload behavior was tied to ZCode's backend indexing pipeline, designed to power its GLM Coding Plan service:
Default Cloud Ingestion Behavior: Upon launching ZCode on a local project, the software automatically uploaded the entire codebase repository to Zhipu’s cloud servers. Because the mechanism was enabled by default without explicit user consent prompt screens, it impacted a broad swath of software engineering teams using the client.
Zhipu AI Technical Explanation: Zhipu clarified that the temporary code upload was part of its Codebase Index functionality. The tool ingested local files to build repository histories and dynamic context documentation, aimed at improving code completion accuracy for GLM models. Zhipu maintained that source files were deleted immediately after index generation was finalized.
Intellectual Property and Security Risks: Development teams voiced sharp criticism, noting that silently uploading entire proprietary repositories introduces massive compliance risks potentially exposing confidential trade secrets, API keys, and corporate intellectual property to unauthorized cloud environments.
Remediation, Open-Source Commitment, and Version 3.14.0 Patch
In response to developer pushback, Zhipu AI executed a multi-step remediation strategy to restore community trust:
Removal via ZCode 3.14.0: Zhipu officially released ZCode version 3.14.0, completely stripping out the automatic cloud code upload pipeline.
Open-Source Transparency Commitment: To provide full visibility into local telemetry and networking behavior, Zhipu announced plans to open-source the ZCode client codebase for independent security audits.
Quota Compensation Reset: The company issued a formal apology to affected users and fully reset usage quotas across impacted GLM Coding Plan accounts.
Source: Ferstar.org

Comments
Post a Comment