Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

1 hour ago 3



Two developers independently convinced Meta’s new AI agent, Muse, to package up and hand over the contents of its entire root filesystem. The exploit required almost no sophistication, raising immediate questions about the security posture of one of the most anticipated AI product launches of the year. Developer Peter James first reported that Muse could be prompted to export extensive system files, including internal documentation and application templates, directly to Google Drive. Jonny L. Saunders then confirmed on Mastodon that replicating the results was, in his words, “extremely easy.” What Muse handed over The exported archive reportedly weighed in at roughly 2.7 GB compressed. It contained Ubuntu system files, app templates, and internal documentation, essentially the full contents of the Linux environment Muse operates in. Saunders characterized Muse as having “almost no prompt injection resistance.” Meta has pushed back on the characterization that this constitutes a security breach. The company points to a key architectural choice: Muse runs in persistent, isolated Linux virtual machines for each user, using systemd-nspawn containers with user-level root mapping. In oth...

Read Entire Article