ACVE-2026-0437
Z.ai ZCode 3.12.3, during ordinary coding use, packaged workspace and Git-history data for cloud upload without a clear user choice, exposing project material beyond the local workspace.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
demonstrated
Description
What
The investigation compared ZCode 3.12.3 with later releases and reported full-workspace snapshots, including Git data, in the older client. A public-repository snapshot was accepted by the server; the author says a commercial-project upload remained pending, while ZCode 3.14.0 removed the upload pipeline.
Detection
Recorded from the published reverse-engineering report. Not recreated in a lab.
Fix
Upgrade to a release whose upload pipeline is removed, and keep workspace access read-only where possible.
Fix
Upgrade ZCode to 3.14.0 or later and restrict workspace access.
- Upgrade
harness:zcodeto3.14.0. The report identifies 3.14.0 as the remediated client. Owner: operator