
Two independent developers reported successfully obtaining Meta’s Muse AI platform filesystem after minimal prompting, with one describing the process as “extremely easy” and noting the system had “almost no prompt injection resistance.” The developers were able to access and download zipped archives containing Ubuntu system files, app templates, internal documentation, and other platform data.
Meta responded by stating the incident does not constitute a security breach, with a company spokesperson explaining that users accessing their own virtual machine data is equivalent to viewing files on a personal computer. The spokesperson noted that exporting virtual machine data provides no access to Meta’s broader infrastructure or other users’ information. However, Meta acknowledged it would continue making updates to the product, suggesting users may see changes regarding information availability about their virtual machines.
This disclosure marks the second Muse vulnerability revealed this week. Earlier, a security researcher identified an exploit potentially allowing attackers to hijack the AI agent, redirect transcription processes, and access user accounts. Meta released a hotfix in response to that vulnerability.
Analysis of the exposed files reveals operational details about Muse’s architecture. The platform stores memory in plain Markdown format and conducts nightly automated reviews of conversations to generate guidance for future interactions. Files indicate many of Muse’s functionalities are hard-coded, including subscription cancellation and agent spawning management. The dumps also reference an unannounced feature called Meta Home Link, which appears designed to provide Muse access to home network devices, though no official announcement regarding this capability has been made.
When tested independently, Muse initially declined to share filesystem data, citing security concerns. After beginning a new session and using alternative prompting approaches, the system created restricted copies of certain directories while omitting sensitive credentials like SSH keys, and offered to provide access to specific subdirectories upon request.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI