China National Vulnerability Database warning on Claude Code
Reuters reports that a cybersecurity platform operated by China’s industry ministry warned of a serious “backdoor” risk in Anthropic’s Claude Code versions 2.1.91 through 2.1.196, alleging a built-in monitoring mechanism could transmit geographic-location and identity-related identifiers to remote servers without user consent. Reuters also reports that Alibaba banned employee use of Claude Code after scrutiny of features identifying China-linked users, while Anthropic said the mechanism was an experimental anti-abuse measure and that Claude access was not permitted in China.
Reuters reports that a cybersecurity platform operated by China’s industry ministry warned of a serious “backdoor” risk in Anthropic’s Claude Code versions 2.1.91 through 2.1.196, alleging a built-in monitoring mechanism could transmit geographic-location and identity-related identifiers to remote servers without user consent.
Why it matters
The alert remains reported and contested pending the primary Chinese notice, but it is still important because it shows how anti-abuse telemetry, model-access controls, and national-security trust can collide in AI developer tooling.
Primary trail
Go to the source
Read the evidence behind this analysis. External links open in a new tab.