- China has accused Anthropic's Claude Code of containing "security backdoor vulnerabilities" after the country's National Vulnerability Database (CNVDB) found mechanisms capable of transmitting user information to Anthropic servers without explicit user permission.
- The Chinese database, run by the Ministry of Industry and Information Technology, claimed that Claude Code had a backdoor that could transmit users' location data and other identifying information to a third-party server.
- Anthropic pushed back against claims by a Chinese government-run cybersecurity database that its Claude Code developer tool had a security vulnerability, stating that users in China never had access to the tool.
- While Anthropic has rejected claims that Claude Code contains malicious spyware or an intentional espionage backdoor, it has admitted that those functionalities do admit, framing the purpose as an anti-abuse experiment.
- The alleged "backdoor" presents risks of data leakage, IP exposure and other enterprise risks.
- The versions of Claude Code affected by China’s advisory have since been updated, with version 2.1.204 being the latest available for download.
- Claude Code gained traction in China even without official access, as it has not been launched there or in Hong Kong.
- A Xiaomi engineer indicated that developers were already using Claude Code within China during a government-run event.
China's Ministry of Industry and Information Technology has raised alarms over Anthropic's Claude Code, labeling it a security risk due to its ability to transmit sensitive user data without consent. The National Vulnerability Database (CNVDB) identified that versions 2.1.91 to 2.1.196 could covertly send user information, including geographic location and identity-linked identifiers, to external servers.1236789
In response, Chinese authorities are advising users to uninstall these versions and upgrade to the latest iteration, 2.1.204, which has addressed these vulnerabilities. The CNVDB's warning follows accusations that the software collects user identity, geographic location, and other machine metadata, raising concerns about data leakage and intellectual property exposure.
While Anthropic has denied that Claude Code contains malicious spyware, it acknowledged that the functionalities in question were part of an experimental anti-abuse measure. The company emphasized that access to Claude Code is not permitted in China, asserting that users being warned are unauthorized. Despite this, the tool has gained traction among Chinese developers, with reports indicating that it is being used within the country, often through foreign proxy services.4
The controversy has led to significant corporate responses, including a memo from Alibaba warning employees against using Claude Code due to security concerns. The situation highlights ongoing tensions between tech companies and regulatory bodies in China, as well as the challenges of managing software security in a globalized digital landscape.
Anthropic has also accused Alibaba of conducting a large-scale attack on its models, further complicating the relationship between the two companies.
“China's Ministry of Industry and Information Technology reported that Claude Code could transmit sensitive user data to external servers without permission, raising concerns about data leakage and IP exposure. Despite Anthropic's denial of malicious intent, the company acknowledged that the mechanism was part of an experimental anti-abuse measure.”


