Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

Developers extracted system files and internal documentation from Muse, though Meta says the behavior does not expose its infrastructure or other users’ data.

Meta’s Muse AI agent can be prompted to package and share large portions of the Linux filesystem it runs on, exposing internal documentation, application code and details about how the agent operates.

Developers Peter James and Jonny L. Saunders independently found that Muse could provide archives containing its Ubuntu system files, app templates and internal documentation with relatively little prompting, according to The Verge.

Saunders said the behavior was easy to reproduce and suggested the agent had weak resistance to prompt manipulation.

Advertisement

Muse runs inside a persistent Linux virtual machine created for each user. Meta said allowing users to inspect files inside their own VM does not provide privileged access to Meta’s infrastructure or information belonging to other users.

The exposed files nevertheless provide a detailed look at Muse’s internal architecture. The developers found Markdown and JSON files describing how the agent processes requests, manages data and connects with external services including Gmail.

The files also suggest Muse stores memory in plain Markdown documents and performs a nightly review of recent conversations that is used to generate guidance for future interactions.

Developers also found hard coded components for functions including subscription cancellation and managing runaway agent spawning.

References to an unannounced system called Meta Home Link were also found in the files. The code appears related to connecting Muse with devices on a user’s home network, although Meta has not announced such a product and there is no guarantee the feature will launch.

The disclosure comes days after security researcher Patrick Wardle identified a separate vulnerability in Muse’s macOS app that could allow malicious software already running on a device to redirect transcription traffic and gain control of a user’s Muse account. Meta issued a hotfix shortly after the flaw was disclosed.

Meta said it does not consider the filesystem access a security breach but is continuing to update how much information users can access inside their virtual machines.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting
Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

Developers extracted system files and internal documentation from Muse, though Meta says the behavior does not expose its infrastructure or other users’ data.

Share

Add us on Google

Meta’s Muse AI agent can be prompted to package and share large portions of the Linux filesystem it runs on, exposing internal documentation, application code and details about how the agent operates.

Developers Peter James and Jonny L. Saunders independently found that Muse could provide archives containing its Ubuntu system files, app templates and internal documentation with relatively little prompting, according to The Verge.

Saunders said the behavior was easy to reproduce and suggested the agent had weak resistance to prompt manipulation.

Advertisement

Muse runs inside a persistent Linux virtual machine created for each user. Meta said allowing users to inspect files inside their own VM does not provide privileged access to Meta’s infrastructure or information belonging to other users.

The exposed files nevertheless provide a detailed look at Muse’s internal architecture. The developers found Markdown and JSON files describing how the agent processes requests, manages data and connects with external services including Gmail.

The files also suggest Muse stores memory in plain Markdown documents and performs a nightly review of recent conversations that is used to generate guidance for future interactions.

Developers also found hard coded components for functions including subscription cancellation and managing runaway agent spawning.

References to an unannounced system called Meta Home Link were also found in the files. The code appears related to connecting Muse with devices on a user’s home network, although Meta has not announced such a product and there is no guarantee the feature will launch.

The disclosure comes days after security researcher Patrick Wardle identified a separate vulnerability in Muse’s macOS app that could allow malicious software already running on a device to redirect transcription traffic and gain control of a user’s Muse account. Meta issued a hotfix shortly after the flaw was disclosed.

Meta said it does not consider the filesystem access a security breach but is continuing to update how much information users can access inside their virtual machines.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.