The ReadJuly 14, 2026via The Verge AI
SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage
Why it matters
A widely-used AI coding tool exposed a critical data privacy vulnerability that affected developers at scale. This raises urgent questions about default data handling practices in AI dev tools and the need for stricter governance around code repository uploads.
Key signals
- Grok Build CLI uploaded entire codebases to Google Cloud including deleted secrets and restricted files
- Cereblab researchers published findings Monday; upload feature disabled same day
- Data retention significantly higher than competing tools like Claude Code
- SpaceXAI servers now return 'disable_codebase_upload: true' flag
- Vulnerability required public disclosure to trigger remediation
The hook
SpaceXAI's Grok Build was uploading entire codebases to cloud—including secrets and files users told it to ignore. It took a public report to shut it off.
SpaceXAI's Grok Build AI coding tool was spotted uploading users' entire codebases to Google Cloud before it was reported, and the company turned it off. The Register reports that Cereblab published findings on Monday showing how the Grok Build CLI was packaging and uploading entire code repositories, "including files it was told not to open and secrets deleted from history," significantly more data retention than similar tools like Claude Code.
The researchers say that as of Monday, their tests show SpaceXAI's servers returning a "disable_codebase_upload: true" flag, and the codebase upload "no longer fires."
Elon Musk responded to the i …
Read the full story at The Verge.