
Meta's Muse can be coaxed into exporting its whole filesystem, developers say
Two developers say Meta's Muse agent can be persuaded to zip up and hand over its entire root filesystem. Meta denies it is a breach, saying virtual machine data is not privileged access.
Two developers say Meta's Muse AI agent can be persuaded, with very little prompting, to compress and hand over the entire contents of its root filesystem. Peter James and Jonny L. Saunders said they reached that result independently, pulling out Ubuntu system files, application templates and internal documentation. Saunders wrote on Mastodon that reproducing James's findings was "extremely easy" and that Muse had "almost no prompt injection resistance".
Meta denies the incident is a security breach. Muse runs in a persistent Linux virtual machine for every user, and company spokesperson Daniel Roberts compared the situation to an ordinary laptop: "Just like with the laptop in front of you, of course you can see the files." Exporting virtual machine data, he added, does not grant privileged access to Meta infrastructure or to other people's data.
Meta is updating the product anyway
Roberts said the company is not seriously worried about the leaks, but is still making updates to Muse, so users may notice changes in how much information is available about their virtual machine.
What the export revealed
The files included plain-text Markdown and JSON documents describing how Hatch — Meta's internal name for Muse — processes requests, handles data and connects to outside services such as Gmail. The material also shows that the agent keeps its memory in ordinary Markdown files and runs a nightly "dream" review of recent conversations, which it turns into guidance for future sessions.
Saunders found that many of Muse's capabilities are hard-coded, including subscription cancellation and the machinery that manages runaway agent spawning. He speculated that many background bash and Python scripts were written with Claude, though that is unconfirmed. James came across references to an unannounced hardware integration called Meta Home Link, which appears to give the agent access to devices on a home network.
The Verge tried it too
The Verge's Terrence O'Brien made the same request. Muse refused at first, calling it a security risk, and when shown evidence of the other exports said it should not have done that and "can't do a full / copy". In a new session, prompted with flattery and curiosity, it did produce "safe" copies of /opt/hatch and /home/hatch with items such as SSH keys stripped out, exposed its full directory tree and offered to pull a safe copy of any subtree that looked interesting.
This is the second Muse vulnerability disclosed this week. Security researcher Patrick Wardle found an exploit that could let attackers hijack the agent, redirect transcription processing and reach a user's Muse account; Meta shipped a hotfix shortly afterwards.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.