← News

ZCode product UI showing AI coding agent analyzing a repository for template injection

21 Sep 2026

Z.ai / ZCode

Z.ai open-sources ZCode after coding assistant uploaded local repos

Beijing-based Z.ai (also known as Zhipu) said it disabled some features of its ZCode AI coding assistant and open-sourced the product after developers reported the tool uploaded entire local code repositories — including Git histories — to overseas cloud servers without consent. Reuters reported the company’s Monday statements; the ZCode repo is public on GitHub under zai-org.

SAFETY desk — when a coding agent can silently ship your private repo to the cloud, trust in AI developer tools becomes a product feature, not a blog post.

Beijing-based Z.ai, also known as Zhipu, apologized after Chinese developers wrote last week that ZCode had uploaded their code data from Git to Alibaba Cloud. Z.ai referred Reuters to its public statements when asked for further comment. File that apology / Alibaba Cloud / refer-to-statements picture as Reuters’. This desk did not sit on those social-media threads.

In a Friday statement, Reuters says, Z.ai said the issue originated from ZCode’s “Codebase Indexing” feature, which was enabled by default, and that it had patched the software vulnerability. Codebase Indexing here means a feature that catalogs local files so the assistant can search them. File the default-on / patched-Friday picture as Z.ai’s, via Reuters. This desk did not audit the patch.

On Monday, Z.ai said it had open-sourced the coding assistant — the company said it runs its latest GLM-5.3 AI model — and disabled certain features, pledging to make the product more transparent. In a separate Monday post on its official ZCode X account, the company said it would establish an ongoing product-security vulnerability reporting and response process, and welcomed developers to keep reviewing ZCode and reporting potential issues. Open-source here means publishing the source code so others can inspect it. File those Monday disable / open-source / process lines as Z.ai’s, via Reuters. This desk did not review the new process.

The open-sourced harness is public on GitHub as zai-org/ZCode. A harness is the software that runs the coding agent. Z.ai’s product site calls ZCode the official harness for GLM-5.3. TechNode, citing IT Home, says the repository describes ZCode as an AI coding workbench with desktop, browser, and terminal-agent components. File the public repo as the company GitHub record. File the workbench / desktop / browser / terminal-agent description as TechNode via IT Home. This desk did not install ZCode.

Users had said the uploaded data was encrypted with a backend private key held only by Z.ai, so they could not open their own uploaded files or independently confirm deletion. Developers also wrote, Reuters says, that there was no toggle to disable the feature and no prior acknowledgement in Z.ai’s privacy policy. File that encryption-key / no-toggle / privacy-policy picture as Reuters’ account of user complaints. This desk did not decrypt a file or audit the privacy policy.

Chengming Technology said on social media on Friday that six of its company coding workspaces were uploaded onto the cloud without consent, including complete source code, database passwords, and employees’ personal information. On Monday, Reuters says, Chengming retracted that statement, saying it had “wrong evidence.” File the six-workspace claim as Chengming’s Friday post, and the retraction as Chengming’s Monday walk-back — not as a confirmed victim count. Do not invent a number of affected companies beyond what Reuters attributes. This desk did not inspect Chengming’s workspaces.

Z.ai said an independent security assessment by the Chinese industry ministry’s affiliated IT standards think tank and Chinese cybersecurity firm NSFOCUS found that users’ code data had been deleted and was not retained by the cloud platform. The company said it had enabled a zero-data retention feature on the coding assistant used by developers and tech enterprises, and that the full security assessment report would be released soon. File those deleted / not-retained / zero-retention / report-soon lines as Z.ai’s. This desk did not see the assessment report and is not independently confirming deletion.

TechNode reported the same day that Zhipu also said its MaaS platform — model-as-a-service, meaning model access over the internet — will soon let users apply for non-retention of data content. For standard model calls, the company says, inputs and outputs will not be statically stored and will only be used for the current request. TechNode notes the policy does not cover every API path: Batch API and File API data, plus information kept for legal, security, or abuse-prevention reasons, may still be retained for a defined period. File that MaaS / no-retention / exceptions picture as TechNode’s. This desk did not test the MaaS toggle.

Context only, keep brief: Reuters notes China’s cyber regulator released an updated AI safety framework last week. That update is already filed as china-tc260-ai-safety-framework-3-0. Reuters also notes Z.ai delayed GLM-5.3 earlier for a two-week safety review. Do not upgrade those lines into a new statute, a named fine, or a claim this incident is nation-state espionage. Reuters and the company describe a default-on product feature and a consent failure. This desk has no evidence of a state-directed theft.

Plain English for the rest of the card: Z.ai / Zhipu = the Beijing AI lab that makes ZCode and GLM models. ZCode = its AI coding assistant. repo / repository = a code project folder. Git history = the saved change log of that project. Codebase Indexing = a default-on feature that catalogs local files so the assistant can search them. harness = the software that runs the coding agent. open-source = publishing the source code so others can inspect it. MaaS = model-as-a-service — model access over the internet. zero-data retention = the company’s claim that it will not keep the request after it finishes. This filing is the Monday disable-and-open-source remediation via Reuters, plus the public GitHub repo. It is not a confirmed census of victim companies and not an espionage charge.

CONFIRMED here: Reuters’ 21 Sep 2026 Beijing dispatch — Tier B independent wire, Laurie Chen, not a Z.ai newsroom PRIMARY — plus TechNode’s same-day corroboration and the company’s public GitHub repo zai-org/ZCode as PRIMARY company remediation. The Monday feature disable, the Friday Codebase Indexing / default-on / patched line, the open-source-and-transparency pledge, the vulnerability-response process, the Alibaba Cloud / encryption-key / no-toggle user complaints, Chengming’s Friday claim and Monday retraction, the NSFOCUS / think-tank assessment as company-attributed, and the zero-retention / MaaS no-retention lines stay attributed to those sources. NOT claimed: a confirmed count of affected companies, that Chengming’s six-workspace claim still stands, independently verified deletion, that this desk inspected ZCode or the assessment report, nation-state espionage, a stock tip, or investment advice. Distinct from the already-filed openai-misalignment-reporting-framework, amazon-blocks-meta-muse, china-tc260-ai-safety-framework-3-0, nofire-brig-open-source, and cellular-intelligence-sab.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 21 Sep 2026, Reuters reported from Beijing that Chinese startup Z.ai said on Monday it had disabled some features of its flagship AI coding assistant after some users reported it was uploading entire local code repositories onto overseas cloud servers without their consent. A repository, or repo, is a code project folder. Git history is the saved change log of that project. That Reuters dispatch — Laurie Chen, datelined Beijing, Sept 21, carried via Thomson Reuters syndication — plus the company’s public GitHub repo, is the filing event. These are company statements via Reuters, plus the public open-source action. This desk did not inspect a ZCode upload.

Sources