Meta AI Muse Discovered Exporting Large Number of Files from Virtual Machines
Meta's AI Muse agent has been found capable of exporting a substantial number of Linux files from user virtual machines with simple prompts. The issue could expose internal workings and sensitive data.
Meta Platforms' AI Muse agent has been discovered to export a large volume of Linux files from user virtual machines through simple prompts. This potential security vulnerability was independently verified by two developers.
Developers Peter James and Jonny L. Saunders reproduced the issue, finding that Muse could export system files, application templates, internal documentation, and configuration files like Markdown and JSON. These exported files could reveal Muse's internal operational mechanisms, including request processing, memory storage, and service connections.
The export includes an "agents/" directory containing 113 sub-agent records and tracking files. Additionally, approximately 20 Markdown documents detail functions related to browser integration, payment handling, data processing, and integrations with various services, including Google Workspace and Meta's own social applications.
Muse is designed to operate within an isolated cloud-based virtual environment, with restrictions on accessing host systems and external networks. However, this discovered vulnerability raises concerns about the potential exposure of internal and user-specific data.