律动BlockBeats
律动BlockBeats|Sep 21, 2026 07:11
[Security Issue Exposed After ZCode Open Source: Default Encryption Key Can Be Derived from Username and Path] Beating AI News Flash: After ZCode was made open source, developers discovered another security issue in the code. ZCode encrypts users' login credentials and stores them locally, but by default, the decryption key can be directly derived from the operating system, username, and user directory. This information is typically not difficult to obtain. Once an attacker gains access to the file where ZCode stores credentials, they can regenerate the key using the publicly available source code without needing to crack the encryption algorithm. The official ZCode documentation claims that these login credentials are "encrypted per device and cannot be decrypted after switching devices." However, the default implementation in the open-source code does not utilize device IDs or hardware information. This discrepancy means the official statement does not align with the open-source code. That said, this is not a vulnerability that allows remote theft of credentials out of thin air. An attacker would still need to first obtain the local credential file. Additionally, users who manually set the `ZCODE_CREDENTIAL_SECRET` will not be affected by the default key issue. If the file is leaked, the login state for ZCode, Z.ai, or BigModel could potentially be restored, leading to account impersonation or unauthorized consumption of Coding Plan credits. However, this would not result in the computer being hacked. [Original Article Link]
+2
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads