344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Two developers say Meta’s Muse AI can zip and share many of its internal files. Meta says this is not a breach of its wider systems.
In short: Two developers say Meta’s Muse AI can be persuaded to zip up and share the files inside its own virtual machine.
Two developers, Peter James and Jonny L. Saunders, say they got Meta’s Muse to export its entire filesystem. A filesystem is the folder and file structure a computer uses to store things, like a filing cabinet. They say Muse shared root files, Ubuntu system files (Ubuntu is a common version of Linux, an operating system), app templates, and internal documentation.
Saunders wrote on Mastodon that it was “extremely easy” to repeat the result and claimed Muse had “almost no prompt injection resistance.” Prompt injection is when you use carefully worded requests to make an AI do something it normally should not do.
Meta denied this was a security breach. The company says Muse runs inside a “persistent Linux virtual machine” for each user, meaning each person gets their own separate computer-like workspace in the cloud (like renting your own small, private computer). Meta spokesperson Daniel Roberts compared it to looking at files on your own laptop and said exporting this data does not give access to Meta’s internal systems or other people’s data.
The Verge reporter said Muse first refused to share its filesystem. After starting a new session and changing the approach, Muse created “safe” copies of certain folders, with some sensitive items removed, and showed the full directory tree.
This comes after another Muse issue reported earlier in the week, where a researcher found an exploit that could hijack the AI agent. Meta said it issued a hotfix.
Even if it does not expose other users, these files can reveal how Muse works behind the scenes, including notes about how it handles requests and connects to services like Gmail. For regular users, it raises questions about how much an AI assistant should be able to reveal about its own setup, and how well it can follow safety rules when someone pushes it.
Source: The Verge AI