Researchers say Meta's Muse AI can be prompted to export its entire filesystem
Developers Peter James and Jonny L. Saunders independently got Meta's Muse AI agent to zip up and share its root filesystem, including Ubuntu system files, app templates, and internal documentation. Saunders said replicating the result was 'extremely easy' and that Muse showed 'almost no prompt injection resistance.' Meta says exporting this virtual machine data is expected behavior and not a security breach, since each user's Muse runs in its own persistent Linux VM.
GoKawiil's interpretation of the reporting above, not reported fact.
The files reportedly expose internal details about how Meta's Muse (internally called Hatch) processes requests and connects to services like Gmail, which could give outsiders insight into the platform's architecture even if no user data is compromised. This is the second Muse-related vulnerability disclosed in a week, following a separate exploit that let attackers hijack the agent, suggesting Muse's security may still be maturing shortly after launch.
- Two developers separately got Muse to export its full filesystem with minimal prompting.
- Meta disputes this is a security breach, saying users can normally view their own VM's files.
- It follows another Muse exploit disclosed days earlier that Meta patched with a hotfix.
Source: theverge.com — Terrence O'Brien, 2026-09-24
Published there as: “Muse will apparently let you download its entire filesystem”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.