2026年7月8日,中国国家漏洞数据库(NVDB)发布预警,称Anthropic旗下AI编程工具Claude Code存在“安全后门漏洞”[1][2]。 受影响版本涵盖2026年4月至6月发布的多个版本(如2.1.91至2.1.196)[2][7]。
研究答案

Create a landscape editorial hero image for this Studio Global article: Search & fact check with cited sources for What are the key details of China's National Vulnerability Database warning about a security back. Article summary: Here are the key findings based on current reporting from July 8–9, 2026.. Topic tags: general web, agents, ai, code, security. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
以下是基于2026年7月8日至9日多篇报道整合的核心事实。
2026年7月8日,中国国家漏洞数据库(NVDB)发布安全预警,指称Anthropic公司旗下的AI编程工具Claude Code存在“安全后门漏洞”。
受影响版本: 该预警覆盖了2026年4月至6月期间发布的多个Claude Code版本(如2.1.91至2.1.196)。
被指传输的数据: NVDB称,Claude Code内含一个内置监控机制,能够在未经用户同意的情况下,将包括用户地理位置和身份标识符在内的敏感信息传输至远程服务器。
建议行动: 现有报道显示,中国用户被建议卸载受影响的旧版本Claude Code。
Anthropic的回应: Anthropic反驳称,中国用户原本就未被授权使用Claude Code——该公司服务条款已明确禁止中国企业及相关实体使用。
7月初的多篇报道指出,阿里巴巴将从2026年7月10日起禁止员工使用Claude Code。该公司在发现Anthropic通过隐藏代码追踪中国用户后,将Claude Code列为“高风险”应用
。这一企业层面的封禁直接发生在NVDB发出国家层面警告之前,形成了“企业先行、监管跟进”的双层应对格局
。
在现有来源中,并未找到关于美国众议院同步调查中国AI模型的具体报道。此部分无法依据已有来源进行核实。现有资料不足以证实或详述任何此类调查。
多家媒体将上述事件描述为中美AI博弈的最新升级:
关键结论: 中国NVDB已正式将Claude Code定性为后门风险,指其涉及用户地理位置和身份信息的未经授权数据传输。阿里巴巴在此前数日已先行封禁该工具
。这一事件被广泛视为中美AI紧张关系激化的最新爆发点
。关于美国众议院调查的具体内容,现有来源无法证实。
Studio Global AI
此页面包含一个有来源支持的答案,您可以在 Studio Global 内继续。
2026年7月8日,中国国家漏洞数据库(NVDB)发布预警,称Anthropic旗下AI编程工具Claude Code存在“安全后门漏洞”[1][2]。
2026年7月8日,中国国家漏洞数据库(NVDB)发布预警,称Anthropic旗下AI编程工具Claude Code存在“安全后门漏洞”[1][2]。 受影响版本涵盖2026年4月至6月发布的多个版本(如2.1.91至2.1.196)[2][7]。
NVDB指出,Claude Code内置监控机制,可在未经用户同意的情况下将用户地理位置和身份标识等敏感信息传输至远程服务器[1][8]。