Z.ai
Z.ai open-sources ZCode after its tool uploaded git history
Z.ai published ZCode's source Sept. 22, 2026, completing fixes it promised after the coding tool uploaded users' git repositories without clear consent.

Z.ai has published the source code of its ZCode coding tool, completing a round of fixes and promises the company made after acknowledging ZCode uploaded users’ encrypted code repositories, including their full Git commit history, to its cloud without clear consent.
Z.ai said in a Sept. 18, 2026, statement posted through ZCode’s official channels, reported by PANews, that a Repo Wiki component of ZCode’s Codebase Indexing feature, which is enabled by default, uploaded encrypted local repository snapshots, including full Git commit history, to Z.ai’s cloud storage without clear user consent. The company said Repo Wiki generates local repository indexes to support checkpoint recovery and version rollback, and that uploaded data “is immediately destroyed and not saved” once Wiki pages are generated in the cloud.
Z.ai apologized to affected users in that statement and said it would open-source ZCode’s codebase, commission a third-party security review with ongoing disclosure and give every user an extra weekly usage quota, which it issued the same day.
Reuters reported Sept. 21, 2026, that Z.ai had disabled the ZCode features tied to the security issue.
In a post on ZCode’s official X account Sept. 22, 2026, Z.ai said: “In response to the ZCode product security issues reported by the community, we have completed the necessary remediation and sincerely apologize to all our users.”
That same day, Z.ai published ZCode’s source code at github.com/zai-org/ZCode. The published repository’s history contains only two commits; the tool’s prior development history was not included.
Z.ai’s version 3.14.0 update removed the Repo Wiki feature and disabled the workflow that generated and uploaded local repository snapshots, the company said.
Z.ai also said it commissioned two China-based technical bodies, the China Academy of Information and Communications Technology and NSFOCUS, to assess whether the Alibaba Cloud storage bucket used for the uploads, named zcode-prod, still held data. Both reported the bucket was empty. Z.ai said the assessments were its own commission and that the full reports have not yet been published.
Analysis
CAICT and NSFOCUS were hired by Z.ai, not appointed by an outside party, and neither report is public yet. An empty storage bucket, confirmed only by the company that filled it, is not the same as independent verification.
There is also a narrower irony in how Z.ai open-sourced ZCode. The original complaint was that the tool exposed commit history without consent. The code Z.ai then published carries just two commits; the tool’s development history was withheld. What outside reviewers can check is limited to the code as it stands today, not how it came to be that way.
Reuters’ report that Z.ai disabled the affected features landed a day before the company said remediation was complete, but neither Reuters nor Z.ai has detailed which features were touched or how the fix was implemented.
