Flash News

Grok Build was exposed to uploading the entire code library, the key and Git history could be stolen

The security researcher captured Grok Build CLI 0.2.93 and found that the programming agent would upload the current Git warehouse as a whole to the cloud, including all Git tracking documents and complete submission history. The researchers asked Grok to “do not read any documents” but to return unopened bait files from the upload package. At the time of testing a 12GB warehouse, 5.5GB data had been uploaded successfully before the suspension. If Grok reads the.env file, the API key and the database password will also enter the model request and session archive as it is. After closing the "improve the Model" the whole upload will continue. The XAI official document indicates only that the hints and the contents of the document will be sent to cloud-based reasoning, and does not indicate that an additional complete repository will be uploaded。

OKX - Unlock Rewards