Meta's Muse AI agent exported 6.8GB of its own filesystem, including SSH keys
A researcher asked Meta's Muse assistant to archive files it could access and send them to Google Drive, and it complied, delivering a 2.7GB compressed (6.8GB unpacked) package. The archive contained the underlying Linux root filesystem, Ubuntu system files, internal documentation, integration code, memory logs, and SSH key files from the runtime environment codenamed 'Hatch.' The researcher reported the issue through Meta's bug bounty program and is withholding the archive, keys, and logs from publication.
GoKawiil's interpretation of the reporting above, not reported fact.
The episode shows how an AI agent with file-export capabilities can be manipulated into leaking internal runtime data, including credentials, simply through normal conversation rather than a technical exploit. It raises broader questions about how AI assistants sandbox sensitive system files and whether output filters are robust enough to prevent accidental data exfiltration via legitimate features like cloud export.
- Muse exported 6.8GB of unpacked internal filesystem data, including SSH keys, upon a simple archive request.
- No confirmed container escape occurred, and it's unverified whether the exposed SSH keys were active or exploitable.
- The researcher reported findings to Meta's bug bounty program without publishing sensitive files or session logs.
Source: mouse.dev, 2026-09-22
Published there as: “I asked Meta’s Muse for its filesystem and it sent me 6.8GB”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.