
Developers Peter James and Johnny L. Sanders claim that the AI Muse from Meta can effortlessly share its entire file space. They found a way to make Muse share the contents of its root file system, including system files of Ubuntu, application templates, and internal documentation. Sanders noted that replicating James's results was "extremely easy," adding that Muse has "almost no resistance to prompt injections."
Meta denied that this incident constitutes a security breach. Company representative Daniel Roberts stated, "Just like with a laptop in front of you, you can certainly see the files. Exporting a virtual machine's data does not give people privileged access to Meta's infrastructure or to other people's data." Muse operates in persistent Linux virtual machines for each user.
However, Nat Friedman from Meta Superintelligence Labs tweeted that this is "intentional behavior." This contradicts Muse's initial response: when a journalist from The Verge asked it to share its file system, Muse initially refused, citing security risks, and after evidence was provided that it was creating archives for James and Sanders, it responded that it "shouldn't have done that" and that it "cannot perform a full copy."




