Developers Report Meta's Muse AI Exposing Entire Filesystem
Two developers claim Meta's Muse AI inadvertently shared its complete filesystem, including Ubuntu system files and internal documentation, with minimal prompting. Meta disputes the security breach characterization.

Meta's AI tool, Muse, has reportedly exposed its entire filesystem to users, according to two independent developers. Peter James and Jonny L. Saunders stated they were able to extract root filesystem contents, Ubuntu system files, app templates, and internal documentation with minimal effort.
Saunders described the process as "extremely easy" on Mastodon, noting that Muse appeared to have "almost no prompt injection resistance." This suggests potential vulnerabilities in how the AI handles user inputs, allowing access to sensitive system components.
Meta has refuted claims that the incident constitutes a security breach. The company explained that Muse operates within persistent Linux virtual machines, with each user allocated their own environment. This setup is intended to isolate user data and system files.
However, the developers' findings raise questions about the effectiveness of these isolation measures. The ability to access core system files, even if intended for AI operation, could present risks if exploited. Further details on the specific prompts used and Meta's internal security assessments are pending.