I asked Meta’s Muse for its filesystem and it sent me 6.8GB
Aeroi
301 points
148 comments
September 22, 2026
Related Discussions
Found 5 related stories in 82.9ms across 7,406 title embeddings via pgvector HNSW
- Muse – Meta’s personal AI agent yks · 434 pts · September 08, 2026 · 57% similar
- Meta’s Muse has a serious 0-day pavel_lishin · 117 pts · September 22, 2026 · 55% similar
- Muse Glimmer is a memory hierarchy disguised as a 30B Transformer stepnivlk · 14 pts · August 18, 2026 · 53% similar
- Muse Spark 1.1 ot · 349 pts · July 09, 2026 · 52% similar
- Muse Spark 1.3 bvaldivielso · 497 pts · September 02, 2026 · 50% similar
Discussion Highlights (20 comments)
Aeroi
I asked Muse to archive the filesystem visible to my session and send it to my Google Drive. It sent an archive that unpacked to about 6.8 GB. Inside were internal docs, integration code, the Spaces app framework, memory records, container startup scripts, and documentation for an experimental ESP32-based home network bridge called Home Link. Codex CLI was also installed, though I found no evidence that Muse invokes it. I didn’t demonstrate a sandbox escape or access to another user’s data. I reported the export to Meta’s bug bounty program, which marked it “Not Applicable.” The post walks through the findings with screenshots. -Pete
Aeroi
original post on x: https://x.com/heypeterjames/status/2102183576418558269
rwmj
Seriously, no bug bounty for that? For exfiltrating the entire content of the system?
tolugenius
> About 20 Markdown files described browser use, connectors, payments, credentials, data handling, generated files, voice, goals, and scheduling. This the state of software engineering in 2026. Edit: clarified engineering to software engineering, which is more correct
ostensible
Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate
rolosa
These files are visible in the muse app by browsing system files.
ecommerceguy
Will Muse cut down on scrolling? I've read about people using it to summarize FB Marketplace listings, cutting down on time spent there. I of course won't use it.
poly2it
Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
noelwelsh
I assume SOUL.md was empty. Seriously, I want to know what's in there!
prodigycorp
The tldr is that muse is heavily inspired by openclaw and should be considered FB’s version of it.
websiteapi
muse is a pretty capable agent but still asks for too many approvals to do tasks. I'm a student and have been going between muse and instinct
Dinux
The internals are not _that_ reveling, most agents run a similar setup. Metas' responds is the most interesting here.
gavinray
> Postgres makes those files searchable. memory.entries stores chunks and line references, memory.embeddings holds 384-dimensional vectors, and memory.claims tracks evidence, confidence, and status. Is each Muse instance running it's own Postgres?? That seems wildly wasteful, especially since earlier in the article it states that the Muse instance has a SQLite database and schema already...
estetlinus
Ah, glad to hear Muse has a Polymarket integration in the pipeline. I mean, what could possibly go wrong?
stephbook
> I’m not publishing the archive, keys, or session logs. Lame
nzoschke
That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work. It gives me a glimmer of hope that openness will win. I don't trust Meta as a corp, but they've been doing the a lot of good things with open source, open models, and developer friendly agents. More thoughts on agent computer architecture here, as I've been building our own open core system for this: https://housecat.com/blog/agent-computer-101
cute_boi
This isn't a bug and doesn't deserves any bounty. Each user gets isolated VM and that is the design and agent is able to access everything.
WhitneyLand
”we've determined that the reported issue does not qualify as a valid vulnerability…because the behavior described is working as intended” So I’m sure they won’t be fixing it then.
MetaverseClub
I have no idea why people would ever want to touch anything from Meta.
munificent
The most potentially dangerous technology in the world is being created by the most irresponsible people on Earth.