A pair of developers have discovered that Meta’s AI, Muse, will share its entire filesystem with very little prompting. Peter James and Jonny L. Saunders were able to coax Muse into zipping up and sharing the root filesystem, Ubuntu system files, app templates, and internal documentation. Meta denies that the incident represents a security breach, instead explaining that users can access virtual machine data without gaining privileged access to infrastructure or other people’s data.
David Singleton, from Meta Superintelligence Labs, tweeted that Muse users should think of it as a ‘free computer in the cloud,’ saying ‘you and your Muse can do almost anything you could with a computer sitting under your desk.’ This is the second Muse vulnerability disclosed this week, following an exploit that allowed attackers to hijack the AI agent, redirect transcription processing, and access a user’s Muse account.
The developers’ dump potentially reveals a lot about Muse’s internal workings, including the storage of its memory in plain Markdown files and nightly ‘dream’ reviews of recent conversations. Many of Muse’s capabilities are hard-coded, including its ability to cancel subscriptions and manage runaway agent spawning. References to hardware integration called Meta Home Link were also found, though its existence is not confirmed. Meta is continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.
While the leak has raised questions about security and privacy, it also opens up a window into how Meta is building and managing its AI platform. Whether this is a breach or a bug, it certainly challenges the idea of AI as a closed system.







