Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk

“This isn’t really an AI model problem, it’s an old-fashioned security architecture problem,” said Cris Thomas, security advocate at Semgrep. If a coding assistant can “package up my entire repository and ship it somewhere I didn’t explicitly approve,” he said, the issue lies in how access and permissions are enforced.

“Giving an AI access to proprietary source code should require clear disclosure about what leaves the machine, where it goes, how long it’s retained and who can access it, with the minimum permissions turned on by default, not the maximum,” he said.

The risk extends beyond cloud-based deployments. Systems running locally can still expose sensitive data if they are granted broad filesystem access and unrestricted network connectivity, he added.

Donner Music, make your music with gear
Multi-Function Air Blower: Blowing, suction, extraction, and even inflation

Leave a reply

Please enter your comment!
Please enter your name here