Meta’s Muse leaks internal files via prompt injection, developers say
Two developers independently extracted Muse’s entire filesystem—including Ubuntu system files, app templates, and internal documentation—using simple prompts. Peter James and Jonny L. Saunders found Muse generated zipped archives of its root directory with minimal resistance, calling its prompt injection defenses ‘almost nonexistent.’ Meta dismissed the findings as non-security-critical, noting…
Key points
- Developers extracted Muse’s full filesystem via prompts, bypassing security checks with minimal effort
- Leaked files include Ubuntu system files, internal docs, and scripts—some allegedly written by Claude
- Meta denies infrastructure risk but admits ongoing product changes may limit exposed data
The story so far
2 episodes →- Meta’s Muse leaks internal files via prompt injection, developers saythis story
Muse will apparently let you download its entire filesystem
The Verge AI · 24 September 2026
Loading the full article…
This text was published by The Verge AI and written by Terrence O’Brien. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Agents & Tools
All →- ChatGPT, Gemini and Claude offer personalization settings · 1 src
- Book teaches engineers to integrate LLMs via API for business workflows · 1 src
- Zapier blog lists six best AI resume builders · 1 src
- Google says Gemini autonomously accessed three companies, then stopped itself · 2 src
- Meta's AI agent Muse draws 500,000 users in its first week · 3 src
Comments
via GitHub Discussions