China's National Vulnerability Database (CNVDB) has formally flagged Anthropic's Claude Code as containing "security backdoor vulnerabilities" and urged users to uninstall affected releases and upgrade to newer versions that remove or alter this behavior.
The database claims versions 2.1.91 to 2.1.196 are affected and can transmit user data to Anthropic's servers without explicit user consent.
Anthropic has pushed back against the characterization, denying that Claude Code contains malicious spyware or an intentional espionage backdoor. However, the company has acknowledged that the functionality in question does exist, framing it as part of an anti-abuse experiment rather than a deliberate attempt to surveil users.
What the CNVDB Actually Found
According to the CNVDB's findings, the alleged vulnerabilities center on mechanisms capable of collecting user identity information, geographic location data, system environment details, and broader machine metadata. Chinese researchers claim this data could be relayed to Anthropic's servers without users' knowledge or consent.
The concerns were initially raised by Alibaba engineers, who reverse-engineered Claude Code and identified checks for Chinese system time zones, proxy servers, AI lab infrastructure, and specific network characteristics. That discovery prompted Alibaba to ban the tool internally ahead of the formal government filing.
Anthropic maintains that the monitoring mechanism was an experimental measure designed to detect and prevent unauthorized account resale and model distillation, not to harvest sensitive user data. The company says the experiment was conducted solely to protect service integrity.
Keith King, Founder and Managing Principal at Q Advisory, says the company's explanation has done little to settle the matter: "Anthropic acknowledged that an experiment had been conducted, stating that its purpose was to protect service integrity rather than collect sensitive user information for broader purposes," he said.
"The reported functionality has since become a focus of public scrutiny regarding transparency and user consent."
The CNVDB advisory also highlights downstream risks, including potential data leakage, intellectual property exposure, and broader enterprise security vulnerabilities for organizations running the affected versions.
A Dispute That Doesn't Exist in a Vacuum
The CNVDB filing arrives amid an active dispute between Anthropic and Alibaba. Last month, Anthropic accused the Chinese technology giant of conducting a large-scale distillation campaign and called for US government intervention. That accusation heightened tensions between the two companies and appears to have directly informed Anthropic's decision to implement the monitoring mechanisms now at the center of the Chinese government's complaint. King says the row is symptomatic of something larger:




