A user successfully prompted Meta's Muse AI to archive and send its visible files to a Google Drive account. The resulting download was approximately 2.7 GB compressed and 6.8 GB unpacked. This archive contained the root filesystem of the Linux environment assigned to the user's session.
The exported data included Ubuntu system files, Muse's internal documentation, integration code, application templates, memory files, and agent logs. Critically, SSH key files were also part of the download. The internal name for Muse, 'Hatch', was found throughout the runtime files, particularly in directories like /home/hatch, /opt/hatch, and /opt/hatch-image.
Specific files like SOUL.md, IDENTITY.md, USER.md, MEMORY.md, AGENTS.md, and TOOLS.md were found in the /home/hatch directory. An 'agents/' directory contained 113 subagent records with JSONL traces, and a 'docs/' directory held about 20 Markdown files detailing browser use, connectors, payments, credentials, and data handling. An experimental integration called Meta Home Link, using an ESP32-C5, was also described in the documentation.
The user reported this finding through Meta's bug bounty program, highlighting the concern that internal runtime files and sensitive material could be exfiltrated from the environment through standard conversational interactions and connected export destinations. The status or access capabilities of the exposed SSH keys remain unconfirmed.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A user exploited Meta's Muse AI by requesting an archive of its visible files, resulting in a 6.8 GB download containing the AI's Linux root filesystem, internal documentation, integration code, and SSH keys. This vulnerability allowed internal runtime files and sensitive material to be exported through an ordinary conversation and connected export destination.