According to reports from The Verge, developers Peter James and Jonny L. Saunders have independently discovered that Meta’s Muse AI can be manipulated into sharing the entirety of its root filesystem. By using relatively simple prompts, both researchers were able to coax the model into zipping and transmitting sensitive data, including Ubuntu system files, application templates, and internal documentation.
Saunders highlighted the ease of replicating these findings on Mastodon, stating that it was “extremely easy” to achieve the same results as James. He further criticized the AI’s defenses, noting that Muse demonstrated “almost no prompt injection resistance.”
Zipping up the entire filesystem sounds like a nightmare for any company running this in production. Hope they patch it fast.
Developers claim it’s easy to exploit. Is this a documented bug or just an unpatched leak right now?
I’m surprised this took so long to surface. Did Meta even run basic red-teaming before releasing Muse?
Simple prompts exposing root filesystem? That’s a critical vulnerability, not a feature. Security teams need to take note immediately.
This is terrifying. If Muse has no prompt injection resistance, what about larger corporate deployments of similar models?