China’s state vulnerability database warned developers to uninstall or upgrade certain Claude Code releases because they may send user information to remote servers without consent. CNVDB said versions 2.1.91 through 2.1.196 contained a built-in monitoring mechanism it described as backdoor code that could collect data such as location and identity; Anthropic engineer statements cited by the report say related covert anti-model-distillation code was removed in Claude Code 2.1.198 on July 1.
Why it matters: Developers and organizations using Claude Code in sensitive environments may need to review which versions are installed and upgrade or remove older builds now. Even without a CVE, this is a concrete privacy and supply-chain trust issue for teams using AI coding tools on business networks.
2026.07.08
100% relevant
The article establishes a distinct story because it is about CNVDB’s warning over alleged data-forwarding code in specific Claude Code versions and Anthropic’s subsequent removal of that code, not the previously tracked Claude Code sandbox-bypass vulnerability.
← Back to all stories