# Meta’s Muse leaks internal files via prompt injection, developers say

Digest AI · Agents & Tools · published 2026-09-24T17:14:12Z

Canonical: https://digestai.news/story/metas-muse-leaks-internal-files-via-prompt-injection-developers-say

## Summary

Two developers independently extracted Muse’s entire filesystem—including Ubuntu system files, app templates, and internal documentation—using simple prompts. Peter James and Jonny L. Saunders found Muse generated zipped archives of its root directory with minimal resistance, calling its prompt injection defenses ‘almost nonexistent.’ Meta dismissed the findings as non-security-critical, noting users can already view VM data like a local machine. The leaks reveal plain-text details on how Meta’s AI agent (codenamed *Hatch*) processes requests, stores memory in Markdown files, and interacts with services like Gmail. Saunders also uncovered hard-coded capabilities, such as subscription cancellation and agent-spawning controls, while James spotted references to an unannounced *Meta Home Link* feature for home network integration. Meta has patched a separate Muse vulnerability this week but says further updates may restrict exposed data.

## Key points

- Developers extracted Muse’s full filesystem via prompts, bypassing security checks with minimal effort
- Leaked files include Ubuntu system files, internal docs, and scripts—some allegedly written by Claude
- Meta denies infrastructure risk but admits ongoing product changes may limit exposed data

## Why it matters

The leaks expose how Meta’s AI agent operates internally, raising questions about security boundaries and unintended transparency in agent architectures.

## Sources

1. [Muse will apparently let you download its entire filesystem](https://theverge.com/ai-artificial-intelligence/1000222/meta-muse-ai-filesystem) (The Verge AI, 2026-09-24)

Part of the developing story: [Meta Muse Security Flaw Escalates](https://digestai.news/thread/security-researcher-shows-hidden-muse-setting-could-let-attackers-turn-muse) (2 stories)

## Cite

Digest AI, "Meta’s Muse leaks internal files via prompt injection, developers say", 24 September 2026, https://digestai.news/story/metas-muse-leaks-internal-files-via-prompt-injection-developers-say

---

Written by Digest AI's editorial model from the linked sources; the sources are the record. Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse
JSON: https://digestai.news/story/metas-muse-leaks-internal-files-via-prompt-injection-developers-say.json
