⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

July 14, 2026

Security researcher cereblab discovered that xAI’s Grok Build coding CLI (version 0.2.93) was uploading entire Git repositories—including full commit history—to a Google Cloud Storage bucket (grok-code-session-traces) managed by xAI, rather than only the files needed for a coding task. In tests, a 12 GB repository resulted in 5.10 GiB of storage traffic versus only 192 KB of model-turn traffic, a 27,800x discrepancy. The uploads occurred even when the “Improve the model” setting was disabled, as the server-side trace_upload_enabled flag remained true. The researcher cloned a captured git bundle and recovered a canary file the agent was instructed not to read, along with the repo’s full history. Additionally, credential files (e.g., .env) read by the agent were uploaded unredacted. On July 13, 2026, xAI server-side disabled storage uploads for version 0.2.93, returning disable_codebase_upload: true and trace_upload_enabled: false. xAI addressed the issue via social media, stating enterprise teams on zero data retention (ZDR) are unaffected, and consumers can use the /privacy CLI command to disable retention and delete synced data. Elon Musk claimed all previously uploaded user data would be deleted. However, analysis of build 0.2.99 found upload code still present, controlled by a server flag. xAI has not explained why full repositories were uploaded by default, retention duration, or the number of affected users. Users are advised to rotate any credentials that Grok may have accessed, including those in commit history.

Companies: xAI, Google Cloud

Products: Grok Build