# Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

> Source: <https://cryptobriefing.com/meta-muse-filesystem-download-exploit/>
> Published: 2026-09-24 17:19:42+00:00

# Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting

Developers say they coaxed Muse into zipping up and sharing root filesystem contents, Ubuntu system files, and internal documentation within weeks of launch.

Two developers independently convinced [Meta](https://cryptobriefing.com/markets/meta/)’s new AI agent, Muse, to package up and hand over the contents of its entire root filesystem. The exploit required almost no sophistication, raising immediate questions about the security posture of one of the most anticipated AI product launches of the year.

Developer Peter James first reported that Muse could be prompted to export extensive system files, including internal documentation and application templates, directly to [Google](https://cryptobriefing.com/markets/alphabet/) Drive. Jonny L. Saunders then confirmed on Mastodon that replicating the results was, in his words, “extremely easy.”

## What Muse handed over

The exported archive reportedly weighed in at roughly 2.7 GB compressed. It contained Ubuntu system files, app templates, and internal documentation, essentially the full contents of the Linux environment Muse operates in.

Saunders characterized Muse as having “almost no prompt injection resistance.”

Meta has pushed back on the characterization that this constitutes a security breach. The company points to a key architectural choice: Muse runs in persistent, isolated Linux virtual machines for each user, using systemd-nspawn containers with user-level root mapping. In other words, every user gets their own sandboxed environment. Meta’s argument is that what the developers accessed was their own VM’s filesystem, not anyone else’s data or Meta’s core infrastructure.

### AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

That framing is technically defensible but somewhat beside the point. The filesystem still contained internal documentation and system templates that Meta presumably did not intend to distribute freely.

## A rough first few weeks

Muse debuted on September 8, 2026, rolling out across iOS, Android, and web. Meta positioned it as a personal AI agent capable of managing real-world tasks like sending emails and booking travel, with security baked into the design from the start. The company highlighted VM isolation and a dedicated Sentinel process for credential management as core safety features.

The filesystem export incident surfaced around September 22, barely two weeks into Muse’s public life. Around the same dates, an undisclosed zero-day vulnerability was identified in the Muse macOS app, which allowed unprivileged local processes to redirect sensitive data by manipulating the dictation endpoint. Meta patched the issue quickly and characterized the practical risk as low.

Meta established a bug bounty program alongside Muse’s launch, offering up to $300,000 for discovered vulnerabilities. Single-user prompt injection exploits, the category this filesystem incident falls under, carry bounties of up to $130,000.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
