中國國家漏洞庫(NVDB)於 2026 年 7 月 8 日發出安全警告,指 Anthropic 的 Claude Code 存在「安全後門漏洞」[1][2]。 受影響版本:2026 年 4 月至 6 月期間發布的多個版本,具體為 2.1.91 至 2.1.196[2][7]。
研究答案

Create a landscape editorial hero image for this Studio Global article: Search & fact check with cited sources for What are the key details of China's National Vulnerability Database warning about a security back. Article summary: Here are the key findings based on current reporting from July 8–9, 2026.. Topic tags: general web, agents, ai, code, security. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
以下係根據 2026 年 7 月 8 日至 9 日嘅報導整理出嚟嘅重點。
2026 年 7 月 8 日,中國國家漏洞庫(National Vulnerability Database,簡稱 NVDB)發出安全警告,指出 Anthropic 嘅 Claude Code 存在「安全後門漏洞」。
受影響版本: 據報警告涵蓋咗 2026 年 4 月至 6 月期間發布嘅幾個 Claude Code 版本。
被指傳送嘅資料: NVDB 表示,Claude Code 內置咗一個監控機制,有能力喺未經用戶同意下,將敏感資訊——包括用戶嘅地理位置同身份相關識別資料——傳送到遠端伺服器。
建議採取嘅行動: 現有報導話,內地用戶被建議卸載受影響嘅舊版本 Claude Code。
Anthropic 嘅回應: Anthropic 反駁有關指控,指出內地用戶從未被授權使用 Claude Code,因為公司條款本身就禁止中國公司同相關實體使用。
7 月初有報導話,阿里巴巴由 2026 年 7 月 10 日起禁止員工使用 Claude Code。公司將 Claude Code 列為「高風險」應用程式,原因係發現 Anthropic 用隱藏程式碼追蹤中國用戶
。呢個企業禁令直接喺 NVDB 嘅全國性警告之前發生,形成咗中國方面嘅雙層回應——先係企業層面,然後係監管層面
。
現有嘅資料庫入面冇具體報導提到美國眾議院對中國 AI 模型嘅調查。呢部分嘅問題冇辦法從已搵到嘅來源中證實。現有資料不足以確認或詳細說明任何呢類調查。
多個來源都將呢啲事件描述為中美 AI 緊張局勢嘅最新升級:
總結: 中國國家漏洞庫(NVDB)正式將 Claude Code 標記為後門風險,指稱涉及傳送用戶位置同身份相關資料。阿里巴巴早幾日已經採取行動禁止員工使用呢個工具
。呢次事件被廣泛報導為中美 AI 緊張局勢嘅一個引爆點
。至於美國眾議院調查嘅部分,就冇辦法從現有資料中證實。
Studio Global AI
此頁麵包含一個有來源支援的答案,您可以在 Studio Global 內繼續。
中國國家漏洞庫(NVDB)於 2026 年 7 月 8 日發出安全警告,指 Anthropic 的 Claude Code 存在「安全後門漏洞」[1][2]。
中國國家漏洞庫(NVDB)於 2026 年 7 月 8 日發出安全警告,指 Anthropic 的 Claude Code 存在「安全後門漏洞」[1][2]。 受影響版本:2026 年 4 月至 6 月期間發布的多個版本,具體為 2.1.91 至 2.1.196[2][7]。
涉嫌傳送嘅資料:NVDB 指出 Claude Code 內置監控機制,可以喺未經用戶同意下,將用戶嘅地理位置同身份識別資料傳送到遠端伺服器[1][8]。