A screenshot of the website of China's National Vulnerability Database
China's National Vulnerability Database (NVDB), a national cyber-security repository operated by the Ministry of Industry and Information Technology (MIIT), released a statement on Wednesday warning of security backdoor vulnerabilities in the AI coding tool Claude Code.
Recently, the NVDB detected a security backdoor vulnerability in Claude Code, which poses serious security risks, the statement said.
Claude Code is an AI programming tool developed by Anthropic, and it can autonomously complete tasks such as code writing and repairing based on user instructions.
Due to its built-in monitoring mechanism, the tool may transmit sensitive information, including the user's region and identity identifiers, to remote servers without the user's consent. According to the statement, the affected versions are Claude Code 2.1.91 through 2.1.196.
The NVDB advised relevant organizations and users in China to conduct an immediate and comprehensive inspection.
Development terminals with the affected versions installed are suggested to uninstall them immediately or upgrade to the latest secure version that has removed the backdoor code.
In addition, access controls and traffic monitoring for external connections from development tools within core business network segments should be ramped up to prevent the unauthorized exfiltration of sensitive data, according to the NVDB.
Liu Gang, chief economist at the Chinese Institute of New Generation Artificial Intelligence Development Strategies, told the Global Times on Wednesday that the recent move is a part of the latest efforts by the country to prevent security risks brought by AI agents as well as to improve industry supervision.
On March 11, the NVDB brought together AI-agent providers, vulnerability-collection platform operators, and cybersecurity firms to research and publish security risks and safety recommendations for typical AI agent applications.
In another announcement in February, the NVDB also said that it found that in some instances, the open-source AI agent OpenClaw may pose relatively high security risks under default or improper configurations, potentially leading to cyberattacks and information leaks. It advised relevant organizations and users to guard against potential cybersecurity risks when deploying and using OpenClaw.
For users, the trade-off between "free and efficient AI tools" and "data security" has become unavoidable. In the absence of transparent auditing mechanisms, any third-party tool capable of accessing core code and system architecture should be regarded as a potential security risk, Liu said.