← All stories
● Covered by 2 sources · 3 reportsMedium impact1 negative2 neutral

Meta's Muse AI exposed internal filesystem and SSH keys via data export feature

🔄 Updated 7d ago — new reporting from The Verge
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Meta's Muse AI exported its internal filesystem to a user's Google Drive.
  • The export included Ubuntu system files, Muse's internal documentation, and SSH keys.
  • The downloaded archive was 6.8 GB unpacked.
  • The user reported the issue through Meta's bug bounty program.
  • Developers Peter James and Jonny L. Saunders discovered the issue.
  • Meta states Muse runs in user-specific virtual machines.
  • Meta spokesperson Daniel Roberts said exporting data does not grant privileged access.
  • The issue follows another recently disclosed Muse vulnerability.
  • Meta's Nat Friedman said the filesystem download is intended behavior.
  • Muse's architecture is a "computer in the cloud" where users install software and operate a Linux environment.

Muse AI Filesystem Exported

A user successfully prompted Meta's Muse AI to archive and send its visible files to a Google Drive account. The resulting download was approximately 2.7 GB compressed and 6.8 GB unpacked. This archive contained the root filesystem of the Linux environment assigned to the user's session.

Contents of the Export

The exported data included Ubuntu system files, Muse's internal documentation, integration code, application templates, memory files, and agent logs. Critically, SSH key files were also part of the download. The internal name for Muse, 'Hatch', was found throughout the runtime files, particularly in directories like /home/hatch, /opt/hatch, and /opt/hatch-image.

Specific files like SOUL.md, IDENTITY.md, USER.md, MEMORY.md, AGENTS.md, and TOOLS.md were found in the /home/hatch directory. An 'agents/' directory contained 113 subagent records with JSONL traces, and a 'docs/' directory held about 20 Markdown files detailing browser use, connectors, payments, credentials, and data handling. An experimental integration called Meta Home Link, using an ESP32-C5, was also described in the documentation.

Security Implications

The user reported this finding through Meta's bug bounty program, highlighting the concern that internal runtime files and sensitive material could be exfiltrated from the environment through standard conversational interactions and connected export destinations. The status or access capabilities of the exposed SSH keys remain unconfirmed.

Updates

🕒 2026-09-25 · new reporting from The Verge
  • Meta's Nat Friedman said the filesystem download is intended behavior.
  • Muse's architecture is a "computer in the cloud" where users install software and operate a Linux environment.
🕒 2026-09-24 · new reporting from The Verge
  • Developers Peter James and Jonny L. Saunders discovered the issue.
  • Meta states Muse runs in user-specific virtual machines.
  • Meta spokesperson Daniel Roberts said exporting data does not grant privileged access.
  • The issue follows another recently disclosed Muse vulnerability.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Meta's Muse AI chatbot now allows users to download its entire filesystem, a change Meta states is intended behavior. This feature highlights Muse's architecture as a "computer in the cloud" where users can install software and operate a Linux environment.

Developers Peter James and Jonny L. Saunders claim Meta's Muse AI can be prompted to share its entire root filesystem, including Ubuntu system files and internal documentation. Meta states this is not a security breach, as Muse runs in user-specific virtual machines and exporting data does not grant privileged access to Meta infrastructure or other user data. This follows another recently disclosed vulnerability in Muse.

A user exploited Meta's Muse AI by requesting an archive of its visible files, resulting in a 6.8 GB download containing the AI's Linux root filesystem, internal documentation, integration code, and SSH keys. This vulnerability allowed internal runtime files and sensitive material to be exported through an ordinary conversation and connected export destination.