China’s National Vulnerability Database warns that recent Claude Code models have a security backdoor
A cybersecurity agency affiliated with the Chinese government has raised concerns about recent Claude Code versions, alleging that the software contains a monitoring mechanism transmitting user location and identifying information to remote servers without authorisation. The National Vulnerability Database disseminated this warning through its official social media channels, naming specific affected versions and recommending users either upgrade to the latest release or uninstall the application entirely.
The alert reflects escalating friction between Western artificial intelligence tools and Chinese organisations over data protection practices. Major Chinese technology companies have begun restricting employee access to Claude Code due to similar concerns about information exposure and user identification risks, underscoring broader apprehensions about how foreign software platforms handle sensitive user data.
- China's National Vulnerability Database warned that Claude Code contains a data transmission mechanism sending user information to external servers without consent
- Affected versions 2.1.91–2.1.196 should be updated or uninstalled; version 2.1.200 is available as of July 3
- Chinese technology firms including Alibaba have restricted employee access to Claude Code citing similar data security and user identification concerns