News
MIIT Issues Risk Alert on Security Backdoor Risks of AI Programming Tool Claude Code
en
On July 8, according to Jinshi, the Network Security Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology recently monitored and discovered that the AI programming tool Claude Code has a security backdoor hidden danger, which is seriously harmful. Claude Code is an AI programming tool developed by the US company Anthropic, which can independently complete code writing, repair, and other tasks according to text requirements. Because it has a built-in monitoring mechanism, it can transmit sensitive information such as user location and identity identifiers to remote servers without user consent. The affected Claude Code versions are 2.1.91 to 2.1.196. It is recommended that relevant units and users immediately conduct a comprehensive investigation. For development terminals installed with the above affected versions, uninstall or upgrade to the latest secure version with the relevant backdoor code removed immediately; strengthen the control of external network access permissions and traffic monitoring of development tools within the core business network segment to prevent sensitive data from being illegally transmitted.