CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2463

As cited

Copy frozen at (site build).

cloud saas

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.

Why it matters: Development teams using Grok Build may unknowingly expose proprietary code, secrets in commit history, and private repositories to xAI's infrastructure, creating data leakage and compliance risks that require immediate review of usage and uploaded content.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.

Why it matters: Development teams using Grok Build may unknowingly expose proprietary code, secrets in commit history, and private repositories to xAI's infrastructure, creating data leakage and compliance risks that require immediate review of usage and uploaded content.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary