Bottom line: ZCode users should exercise extreme caution when using the feature, as the vulnerability could be exploited by attackers to gain unauthorized access to their code repositories.
What's happening: Chinese AI company Z.ai has disabled several features of its ZCode coding assistant due to a default setting vulnerability that allowed users to upload their local code repositories to Alibaba Cloud servers in China without their consent. Researchers from the National Institute of Standards and Technology (NIST) and the University of California, Berkeley identified the vulnerability. The NIST researchers used a proof-of-concept exploit to demonstrate the vulnerability.
What to do: ZCode users should ensure their code repositories are properly secured by using a reputable third-party security solution. Enterprises should also review their cloud computing services to ensure they are properly secured. Note: This vulnerability is related to the CVSS score of 9.3