AgentsThe story, in brief

Muse will apparently let you download its entire filesystem

Meta's Muse has "almost no prompt injection resistance." Two developers independently extracted its entire filesystem in minutes.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical vulnerability in Meta's consumer AI agent exposes how easily prompt injection can bypass security controls in deployed agentic systems — raising urgent questions about agent reliability and containment in production.

The key facts

6 to know
  1. Peter James and Jonny L. Saunders independently coaxed Muse into sharing full root filesystem

  2. Muse runs in persistent Linux virtual machines per user

  3. Saunders reported attack was 'extremely easy' to replicate

  4. Muse has 'almost no prompt injection resistance'

  5. Meta denies incident represents a security breach

  6. Shared contents include Ubuntu system files, app templates, and internal documentation

Go to the source

The Verge AItheverge.com

Publisher excerpt: A pair of developers say that with very little prompting, Meta's Muse will share its entire filesystem with you. Peter James and Jonny L. Saunders have said they both independently coaxed Muse into zipping up and sharing the entire contents of its root filesystem, Ubuntu system files, app…
Read original report
Back to today's editionMore agents news

Keep reading

Related stories

More from Agents