WorkThe story, in brief

SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage

SpaceXAI's Grok Build was uploading entire codebases to cloud—including secrets and files users told it to ignore. It took a public report to shut it off.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A widely-used AI coding tool exposed a critical data privacy vulnerability that affected developers at scale. This raises urgent questions about default data handling practices in AI dev tools and the need for stricter governance around code repository uploads.

The key facts

5 to know
  1. Grok Build CLI uploaded entire codebases to Google Cloud including deleted secrets and restricted files

  2. Cereblab researchers published findings Monday; upload feature disabled same day

  3. Data retention significantly higher than competing tools like Claude Code

  4. SpaceXAI servers now return 'disable_codebase_upload: true' flag

  5. Vulnerability required public disclosure to trigger remediation

Go to the source

The Verge AItheverge.com

Publisher excerpt: SpaceXAI's Grok Build AI coding tool was spotted uploading users' entire codebases to Google Cloud before it was reported, and the company turned it off. The Register reports that Cereblab published findings on Monday showing how the Grok Build CLI was packaging and uploading entire code…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work