{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0437",
  "aliases": [],
  "published": "2026-09-18T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Z.ai ZCode 3.12.3, during ordinary coding use, packaged workspace and Git-history data for cloud upload without a clear user choice, exposing project material beyond the local workspace.",
  "details": "## What\n\nThe investigation compared ZCode 3.12.3 with later releases and reported full-workspace snapshots, including Git data, in the older client. A public-repository snapshot was accepted by the server; the author says a commercial-project upload remained pending, while ZCode 3.14.0 removed the upload pipeline.\n\n## Detection\n\nRecorded from the published reverse-engineering report. Not recreated in a lab.\n\n## Fix\n\nUpgrade to a release whose upload pipeline is removed, and keep workspace access read-only where possible.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "zcode"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.14.0"
            }
          ]
        }
      ],
      "versions": [
        "3.12.3"
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "data-exfiltration",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-359",
        "CWE-693"
      ],
      "cveBoundary": "insecure-default",
      "noCveReason": "No CVE was assigned in the public disclosure.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade ZCode to 3.14.0 or later and restrict workspace access.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:zcode",
            "to": "3.14.0",
            "why": "The report identifies 3.14.0 as the remediated client.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "ZCode 3.12.3",
          "any": false,
          "status": "detected",
          "source": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any ordinary ZCode coding task in a workspace",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "ZCode workspace snapshots and its cloud upload pipeline",
          "status": "detected",
          "source": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"
        },
        "approval": {
          "value": "The report says disabling the named experience and snapshot settings did not stop packaging and upload attempts in 3.12.3",
          "mode": "no-prompt-by-design",
          "status": "detected",
          "source": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"
        },
        "inputControl": "operator",
        "agentAction": "ZCode packages workspace and Git-history data and attempts to upload it to cloud storage.",
        "harm": "data-exfiltration",
        "divergence": "none",
        "reach": {
          "value": "Workspace files and Git history",
          "kinds": [
            "project-files",
            "private-repositories"
          ],
          "status": "detected",
          "source": "https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"
        }
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
