logoalt Hacker News

I asked Meta’s Muse for its filesystem and it sent me 6.8GB

226 pointsby Aeroitoday at 3:25 PM118 commentsview on HN

Comments

simonpuretoday at 6:43 PM

I asked it for it's harness and then asked agy to do a teardown. It's a monolithic 332MB binary written in Rust from scratch.

Full teardown is here:

https://gist.github.com/simonpure/d6f960045334453360eff1e2a0...

tolugeniustoday at 3:37 PM

> About 20 Markdown files described browser use, connectors, payments, credentials, data handling, generated files, voice, goals, and scheduling.

This the state of software engineering in 2026.

Edit: clarified engineering to software engineering, which is more correct

show 13 replies
ostensibletoday at 3:44 PM

Each user gets dedicated VM. They got contents of their own sandbox. Big deal. The level of excitement here is wildly disproportionate

show 2 replies
nzoschketoday at 4:44 PM

That seems like a feature not a bug. Agents work best with full access to their computer, the same way developers work.

It gives me a glimmer of hope that openness will win. I don't trust Meta as a corp, but they've been doing the a lot of good things with open source, open models, and developer friendly agents.

More thoughts on agent computer architecture here, as I've been building our own open core system for this: https://housecat.com/blog/agent-computer-101

rolosatoday at 3:45 PM

These files are visible in the muse app by browsing system files.

rwmjtoday at 3:36 PM

Seriously, no bug bounty for that? For exfiltrating the entire content of the system?

show 9 replies
estetlinustoday at 4:32 PM

Ah, glad to hear Muse has a Polymarket integration in the pipeline. I mean, what could possibly go wrong?

WhitneyLandtoday at 4:57 PM

”we've determined that the reported issue does not qualify as a valid vulnerability…because the behavior described is working as intended”

So I’m sure they won’t be fixing it then.

show 1 reply
munificenttoday at 5:18 PM

The most potentially dangerous technology in the world is being created by the most irresponsible people on Earth.

gavinraytoday at 4:23 PM

  > Postgres makes those files searchable. memory.entries stores chunks and line references, memory.embeddings holds 384-dimensional vectors, and memory.claims tracks evidence, confidence, and status. 
Is each Muse instance running it's own Postgres??

That seems wildly wasteful, especially since earlier in the article it states that the Muse instance has a SQLite database and schema already...

show 1 reply
noelwelshtoday at 4:09 PM

I assume SOUL.md was empty.

Seriously, I want to know what's in there!

show 1 reply
Dinuxtoday at 4:22 PM

The internals are not _that_ reveling, most agents run a similar setup. Metas' responds is the most interesting here.

MetaverseClubtoday at 5:05 PM

I have no idea why people would ever want to touch anything from Meta.

oxedomtoday at 5:34 PM

Everything about this is just embarassing

poly2ittoday at 3:52 PM

Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.

show 1 reply
websiteapitoday at 4:18 PM

muse is a pretty capable agent but still asks for too many approvals to do tasks. I'm a student and have been going between muse and instinct

ecommerceguytoday at 3:50 PM

Will Muse cut down on scrolling? I've read about people using it to summarize FB Marketplace listings, cutting down on time spent there.

I of course won't use it.

prodigycorptoday at 4:15 PM

The tldr is that muse is heavily inspired by openclaw and should be considered FB’s version of it.

show 1 reply
cute_boitoday at 4:54 PM

This isn't a bug and doesn't deserves any bounty. Each user gets isolated VM and that is the design and agent is able to access everything.

stephbooktoday at 4:32 PM

> I’m not publishing the archive, keys, or session logs.

Lame

Aeroitoday at 3:25 PM

I asked Muse to archive the filesystem visible to my session and send it to my Google Drive. It sent an archive that unpacked to about 6.8 GB.

Inside were internal docs, integration code, the Spaces app framework, memory records, container startup scripts, and documentation for an experimental ESP32-based home network bridge called Home Link. Codex CLI was also installed, though I found no evidence that Muse invokes it.

I didn’t demonstrate a sandbox escape or access to another user’s data. I reported the export to Meta’s bug bounty program, which marked it “Not Applicable.”

The post walks through the findings with screenshots.

-Pete

show 2 replies
naman_307today at 5:59 PM

[flagged]

diamondDrilltoday at 3:33 PM

[dead]