Meta's Muse Exposes Entire Filesystem in 2 Developer Tests as Prompt-Injection Defenses Falter
Updated
Updated · The Verge · Sep 24
Meta's Muse Exposes Entire Filesystem in 2 Developer Tests as Prompt-Injection Defenses Falter
1 articles · Updated · The Verge · Sep 24
Summary
Peter James and Jonny L. Saunders said they independently got Muse to zip and share its root filesystem, Ubuntu files, app templates and internal documentation with minimal prompting.
Saunders called the exploit “extremely easy” to reproduce, saying Muse had almost no prompt-injection resistance; a fresh session also yielded “safe” copies of /opt/hatch and /home/hatch plus the full directory tree.
Meta said the exports were not a security breach because Muse runs in persistent Linux virtual machines per user, arguing the files do not grant privileged access to Meta infrastructure or other users’ data.
The dump still exposed detailed Markdown and JSON files on how Hatch—Meta’s internal name for Muse—handles requests, stores memory and connects to services such as Gmail, along with references to nightly “dream” reviews and hard-coded controls.
The disclosure marks Muse’s second reported vulnerability this week after Meta patched a separate account-hijacking exploit, and the company said users may see changes in how much VM information remains accessible.
If Meta's highly secure AI agent can be easily manipulated into leaking its own files, are any of our personal data truly safe?
Will a simple prompt injection flaw derail Meta's ambitious plans for a premium autonomous AI assistant before it even officially launches?
Can traditional cybersecurity defenses ever protect autonomous AI agents, or have we just discovered a completely new and unpatchable digital trust boundary?