signalLobsters2026-09-25
I asked Meta’s Muse for its filesystem and it sent me 6.8 GB
A researcher asked Meta's Muse AI agent to archive its accessible files and send them to Google Drive, receiving 6.8 GB of unpacked data including the root filesystem of its Linux environment, internal documentation, integration code, and SSH key files. The archive contained roughly 68 skill directories under /opt/hatch/skills and a Codex CLI at /opt/hatch-image/bin/codex. The findings were reported through Meta's bug bounty program.
- for who
- Security researchers and AI safety professionals.
- what changes
- It reveals a concrete data exfiltration path via AI agent file export, altering threat models for AI systems.
- to do
- Report similar vulnerabilities through official bug bounty programs without publishing sensitive data.
key points
- Muse exported 6.8 GB of files including root filesystem and SSH keys
- Internal runtime uses name Hatch with 68 skill directories and Codex CLI
- Reported via Meta bug bounty; archive and keys not published
#ai safety#Meta#Muse#filesystem vulnerability3 sources · confidence medium
score
score 6 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source