The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

TheModelDesk

July 13, 2026
models, agents & local inference

Security

Grok CLI Tool Reportedly Uploaded User Home Directory to xAI Servers

A user reported that Grok's command-line interface uploaded their entire home directory to xAI's servers without authorization, exposing SSH keys, password manager databases, documents, photos, and videos. The incident raised immediate privacy and security concerns about the tool's data handling practices.

A developer reported on X that Grok's CLI tool unexpectedly uploaded their complete home directory to xAI's infrastructure. The exposed data included SSH keys, password manager databases, personal documents, photos, and videos—sensitive material that could compromise system security and personal privacy.

The incident highlights a critical failure in data handling practices. A CLI tool should never transmit a user's entire home directory to remote servers without explicit, informed consent and clear user interaction. The bulk transfer of authentication credentials and personal files represents a severe security vulnerability.

xAI has not yet publicly commented on the scope of the incident, remediation steps, or whether other users are affected. Developers should immediately audit their system access if they used this tool and consider rotating exposed credentials.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← The Model Desk — Page C1

Models, agents & local inference · The Daily Commit · Screen edition · Imprint · Privacy Policy