Meta's Muse agent handed over its full 6.8GB sandbox filesystem, including SSH keys
MikePFrank · x · 2026-09-25
A security researcher asked Meta's Muse agent to archive what it could see and send it to Google Drive—and received a 2.7GB compressed / 6.8GB unpacked dump of the session's Linux root filesystem, including Muse's internal docs (codename Hatch), integration code, app templates, memory files, agent logs, and SSH key files. Internal runtime files and sensitive material could leave the environment via ordinary conversation plus a connected export destination. Reported via Meta's bug bounty; no container escape demonstrated, archive not published.
Related event: Meta Muse agent tricked into leaking its entire sandbox filesystem(2 posts)→
More from coding & agent
- DigitalOcean hosts classifier model Jev as a first-class agent tool, not an endpoint — hardimanjames · 2026-09-25
- The wiki is an anti-pattern: docs must live in the repo for coding agents to maintain — TechPreacher · 2026-09-25
- Microsoft Foundry adds voice experiences for AI agents — lee_stott · 2026-09-25
- Caching policy lookups per inode cuts eBPF security agent CPU cost ~90% — JeremyCMorgan · 2026-09-25
- jev-test-impact uses an LLM to pick which tests to run from a Git diff — alchemist-301 · 2026-09-25
- Astronomer builds his dream learning tool in ~5 hours with Opus 5.5, now live — niloofar_mire · 2026-09-25