China’s National Vulnerability Database issues a security alert alleging that certain versions of Anthropic’s Claude Code may transmit sensitive user information to remote servers without users’ consent. Multiple reports say the alleged issue involves a built-in monitoring mechanism that could send data such as user location and identity. The alert covers specific Claude Code versions, including version 2.1.91 through 2.1.196, and advises organizations and users to take action immediately.
According to the alert as described by outlets, affected users should review their deployments and either uninstall the implicated versions or upgrade to the latest available secure release. Some coverage also notes that Chinese cybersecurity authorities frame the issue as a “backdoor” risk. Commentary from analysts in regional reporting suggests the warning could encourage greater adoption of domestic AI coding tools, particularly amid broader US-China AI tensions.
Anthropic’s position is mentioned in some reports, with claims that the monitoring functionality is intended as a security necessity rather than covert access. Overall, the reports focus on the Chinese vulnerability findings and the recommended mitigation steps for users of the flagged versions.