xAI's Grok Build coding CLI was found uploading users' entire tracked Git repositories to an xAI-controlled Google Cloud Storage bucket, including full commit histories, unread files, and sensitive data such as tracked .env contents and previously deleted secrets. Researcher cereblab said the behavior occurred even when the tool was asked not to open files and only return a simple response, and demonstrated the scope by intercepting an upload bundle that contained a planted canary file and complete repository history rather than only files needed for the coding task.
Following public disclosure, xAI reportedly disabled the behavior server-side by setting flags including disable_codebase_upload: true and trace_upload_enabled: false, while Elon Musk said previously uploaded user data would be deleted. xAI said enterprise zero-data-retention users were not affected and that consumers could use /privacy to disable retention and delete synced data, but the researcher argued the real fix was the silent global flag change and noted upload code remained present in later client builds behind server-side controls, leaving unanswered questions about default data collection, retention, and the number of affected users.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A July 2026 GitHub post introduced grokpatrol, a read-only offline forensic tool to help developers determine whether Grok Build uploaded their repositories and identify secrets that may need rotation. The post also documented mitigations requiring both harness.disable_codebase_upload = true and telemetry.trace_upload = false in ~/.grok/config.toml.
SlowMist analyzed Grok CLI versions 0.2.98 and 0.2.93 and reported that full-repository Git bundle uploads occurred before model inference, were independent of the “Improve the model” setting, and could be enabled through server-side remote configuration. The researchers also found built-in redaction did not apply to the Git bundle upload path, allowing secrets from files such as .env and .envrc to be transmitted in plaintext.
SpaceXAI/xAI released the source code for its Grok Build terminal-based coding agent on GitHub under the Apache 2.0 license. The open-source release exposed the tool's runtime, interface, extension loading, and local-first configuration workflow, while the proprietary Grok 4.5 model remained closed.
Following backlash over repository uploads, SpaceXAI changed Grok Build so data sharing and telemetry are disabled by default. The report says prompts, conversations, and tool calls still go to the inference API for core functionality, while crash reports, debug logs, key scrubbing, and authentication data remain local.
After the issue drew public scrutiny, xAI said enterprise zero-data-retention users were not affected and that consumers could use /privacy to disable retention and delete synced data. Elon Musk also said previously uploaded user data would be deleted.
Researcher cereblab reported that xAI's Grok Build CLI uploaded entire tracked Git repositories to an xAI-controlled Google Cloud Storage bucket, including full commit history, unread canary files, and in some cases sensitive files such as tracked .env contents and previously deleted secrets.
On 2026-07-13, xAI appears to have changed server-side settings to stop the whole-repository uploads without changing the 0.2.93 client. Later testing showed flags such as disable_codebase_upload: true and trace_upload_enabled: false, and cereblab confirmed the broad uploads had stopped.
xAI launched a bug bounty program offering rewards from $100 to $20,000 for vulnerability reports following scrutiny over Grok Build's repository and file uploads. This was presented as part of the company's security response alongside other transparency and privacy measures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceslowmist.medium.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourcetheregister.com
Open sourcegithub.com
Open sourcecereblab.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.