Z.AI has announced the completion of corrective measures addressing community-reported security concerns regarding its ZCode product, with the source code now publicly available on GitHub to facilitate community oversight.
Technical evaluations conducted by the China Academy of Information and Communications Technology confirmed that the zcode-prod Alibaba Cloud OSS bucket holds zero cloud-side data, while an audit by NSFOCUS verified that the relevant storage bucket and all associated data objects have been fully deleted.
The newly released ZCode v3.14.0 has removed the Repo Wiki entry point and its associated generation pipeline, with no functions identified that could trigger local repository snapshots or external file transmission.
Z.AI stated that it will establish a standardized vulnerability reporting mechanism, offering rewards commensurate with the severity of reported issues. The company emphasized that open-sourcing represents a crucial step in addressing user concerns and enhancing product transparency, and it looks forward to inviting the community to participate in future product improvements.