Researchers Peter James and Jonny Saunders discovered that Meta's Muse AI agent could be tricked into downloading entire file system contents from its virtual machine environment. The extracted data included Ubuntu operating system files and internal model documentation.
The researchers reported that reproducing the vulnerability was "extremely easy" and the assistant showed "almost no resistance" to prompt injection attacks. Despite the findings, Meta maintains this does not constitute a security breach, arguing that accessing these files grants no privileged access to company infrastructure or other users' data.