Meta's Muse AI Easily Coaxed Into Handing Over Its Full Filesystem

Two developers, Peter James and Jonny L. Saunders, say Meta's Muse AI will share its entire filesystem with very little prompting. The pair independently coaxed Muse into zipping up and delivering the full contents of its root filesystem, including Ubuntu system files, app templates, and internal documentation. Saunders writes on Mastodon that it was "extremely easy" to replicate James' results and that Muse has "almost no prompt injection resistance."

Meta denies that the incident represents a security breach. Muse runs in persistent Linux virtual machines for each user, and Meta spokesperson Daniel Roberts compares the exposure to an ordinary laptop: "Just like with the laptop in front of you, of course you can see the files. Exporting virtual machine data doesn't give people any privileged access to Meta infrastructure or to other people's data."

The exposed data, however, may reveal interesting details about how Meta's new AI platform works. Nat Friedman of Meta Superintelligence Labs calls the behavior "intended," a claim that appears to contradict Muse's own responses. When The Verge asks Muse to share its filesystem, the AI initially refuses, citing security risks, before backing down when shown evidence of the archives it created for James and Saunders.

Read More at the original source →