Meta's Muse AI agent tricked into sharing its entire filesystem with minimal prompting

The Verge AI · rss · 2026-09-25

Developers Peter James and Jonny L. Saunders independently got Meta's consumer agent Muse to zip up and share its entire root filesystem — Ubuntu system files, app templates, and internal docs — with minimal prompting. Saunders called it "extremely easy" to replicate, noting Muse has "almost no prompt injection resistance." Meta denies a breach, saying Muse runs in per-user persistent Linux VMs. The incident highlights how weak consumer agents remain against prompt injection even with VM isolation.

Original post →

More from Safety

Safety channel →