English

SecurityMetaMuse

Meta's Muse AI Vulnerability Allows Access to Entire Filesystem

Developers Peter James and Jonny L. Saunders have demonstrated that Meta’s AI agent, Muse, can be prompted to share its entire filesystem. Through simple prompting, the developers reportedly coaxed the AI into zipping and sharing contents including root filesystem files, Ubuntu system files, app templates, and internal documentation. Saunders noted that the agent showed almost no resistance to prompt injection.

Meta has denied that the incident constitutes a security breach. A Meta spokesperson, Daniel Roberts, explained that Muse operates within persistent Linux virtual machines dedicated to each user. According to Roberts, viewing these files is similar to accessing files on a personal laptop and does not grant privileged access to Meta's broader infrastructure or other users' data.

The leaked data, which included plain-text Markdown and JSON files, provides insight into how Muse—internally known as Hatch—processes requests and connects to services like Gmail. The files reveal that the agent stores its memory in Markdown files and performs a nightly "dream" review of recent conversations to build guidance for future interactions. Additionally, files showed references to a hardware integration called "Meta Home Link," which reportedly grants Muse access to devices on a home network, though Meta has not officially announced this feature.

This incident follows another Muse vulnerability disclosed earlier this week, where a researcher found an exploit allowing attackers to hijack the AI agent. Meta has since issued a hotfix for that specific issue.

Sources

  1. Muse will apparently let you download its entire filesystem (The Verge AI, 2026-09-24)