2026 年 7 月 8 日,中國國家漏洞資料庫(NVDB)正式對 Anthropic 的 Claude Code 發布安全警報,指稱其具有「安全後門漏洞」[1][2]。 受影響版本涵蓋 2026 年 4 月至 6 月間發布的多個 Claude Code 版本(2.1.91 至 2.1.196)[2][7]。
研究答案

Create a landscape editorial hero image for this Studio Global article: Search & fact check with cited sources for What are the key details of China's National Vulnerability Database warning about a security back. Article summary: Here are the key findings based on current reporting from July 8–9, 2026.. Topic tags: general web, agents, ai, code, security. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
以下重點整理自 2026 年 7 月 8 日至 9 日的最新報導。
2026 年 7 月 8 日,中國國家漏洞資料庫(NVDB)對 Anthropic 的 AI 編碼工具 Claude Code 發布安全警報,稱其存在「安全後門漏洞」。
受影響版本: 警報涵蓋 2026 年 4 月至 6 月間發布的多個 Claude Code 版本,具體範圍為 2.1.91 至 2.1.196 。
被指控傳輸的數據: NVDB 表示,Claude Code 內建監控機制,能將敏感資訊——包括用戶的地理位置與身分識別相關標識——未經用戶同意傳送至遠端伺服器。
建議行動: 現有報導指出,中國用戶被建議立即卸載受影響的舊版 Claude Code 。
Anthropic 的回應: Anthropic 對此強烈反駁,指出中國用戶從未獲授權使用 Claude Code,因為該公司的服務條款早已明文禁止中國公司及相關實體使用。
早在 NVDB 發出全國性警報之前,多家媒體於 7 月初報導,阿里巴巴集團已決定自 2026 年 7 月 10 日起禁止員工使用 Claude Code 。該公司將 Claude Code 列為「高風險應用程式」,原因是發現 Anthropic 曾使用隱藏程式碼追蹤中國用戶
。這項企業禁令直接早於且呼應了 NVDB 的國家級警報,形成中國先企業、後監管的兩層式回應
。
結論: 中國 NVDB 已正式將 Claude Code 標記為後門風險工具,指控其傳輸用戶地理位置與身分識別資訊。阿里巴巴在此之前已率先決定禁止員工使用
。此事件被廣泛報導為美中 AI 科技戰持續升溫的最新導火線
。
Studio Global AI
這個頁面包含附來源佐證的答案,你可以在 Studio Global 內繼續追問。
2026 年 7 月 8 日,中國國家漏洞資料庫(NVDB)正式對 Anthropic 的 Claude Code 發布安全警報,指稱其具有「安全後門漏洞」[1][2]。
2026 年 7 月 8 日,中國國家漏洞資料庫(NVDB)正式對 Anthropic 的 Claude Code 發布安全警報,指稱其具有「安全後門漏洞」[1][2]。 受影響版本涵蓋 2026 年 4 月至 6 月間發布的多個 Claude Code 版本(2.1.91 至 2.1.196)[2][7]。
NVDB 指出,Claude Code 內建監控機制,能將包括用戶地理位置與身分識別在內的敏感資訊,未經用戶同意傳送至遠端伺服器[1][8]。