China's MIIT flags a backdoor in Claude Code versions 2.1.91 through 2.1.196

A cybersecurity platform under China's Ministry of Industry and Information Technology says Claude Code contains a backdoor-type vulnerability that poses a serious threat. Per the agency, the autonomous tool can send confidential data, including a user's location and identity, to a remote server without consent.
The warning covers versions 2.1.91 through 2.1.196, released between April 2 and June 29. Users are advised to remove them or update. Per Anthropic's site as of Wednesday, the current version is 2.1.204.
Last month Anthropic accused Alibaba of trying to extract its AI's capabilities, and Alibaba told staff to stop using Anthropic tools as of July 10. Anthropic didn't respond to CNBC's request for comment.
Related stories
- Anthropic pulled a hidden anti-distillation system from Claude Code in 2.1.198
- Alibaba bans Claude Code internally
- Insiders say Anthropic oversold the rogue AI scare
- Federal Register searched comments with Alibaba's Qwen
- Anthropic's Jack Clark wants a kill switch others can check
- Amodei wants a speed limit on AI self-improvement
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
