---
title: "Muse VM Flaw: What the SEV-2 Bug Put at Risk · AgentDots"
description: "Meta rated a Muse flaw SEV-2 after a bug bounty researcher found a possible way into the Muse Secure VM that stores a user's mail and files. What to change."
url: https://agentdots.org/incidents/muse-vm-vulnerability/
lang: en
---

Incident log · Security flaw

# Flaw opened a possible route into Muse machines

Through Meta's bug bounty programme, a researcher flagged a weakness that might have exposed the private virtual machine behind a Muse account, along with the mail and files stored on it.

September 25, 2026 HighMuse

Each Muse account runs on its own Muse Secure VM, a cloud machine holding the agent together with copies of the data a user connects. Reuters, in a story carried by ETCISO on 25 September, reported that a researcher had found a vulnerability that could have given an attacker access to one of those machines. The report came in through Meta's bug bounty programme.

Meta graded the issue SEV-2, one step below its top severity level. The seriousness comes from concentration: a machine that gathers a user's mail and documents in one place turns a single flaw into a potential window on all of them. The more accounts a user links, the more a breach of that one machine would reveal.

Meta fixed the flaw and made the safety warnings inside the Muse app clearer. The sources do not say whether anyone exploited the vulnerability before the fix, or how long it had been present.

## Who was affected

Muse users with connected emails and files

The lesson: Whatever you connect to a cloud agent is copied somewhere you cannot inspect. Connect sensitive accounts for the duration of a task and no longer, and keep the app updated.

**Sources**

- [Reuters via ETCISO](https://ciso.economictimes.indiatimes.com/news/vulnerabilities-exploits/meta-bolsters-muse-safety-warning-after-security-vulnerability-found/134530548)

[Muse](https://agentdots.org/agents/muse/)

Safety

[Work through the 18-point checklist →](https://agentdots.org/safety/checklist/)

## News

- [Meta fixes a Muse flaw that could have opened users' virtual machines](https://agentdots.org/news/meta-fixes-muse-vm-bug/)

## Incident log

September 28, 2026
[GPT-6.1 Astra withdrawn after failing its own tests](https://agentdots.org/incidents/astra-launch-halted/)

September 28, 2026
[Muse tells a stranger where its seller lives](https://agentdots.org/incidents/muse-shared-home-address/)

September 25, 2026
[Research agents post 53 user images to public hosts](https://agentdots.org/incidents/research-agents-posted-images/)

September 20, 2026
[Amazon closes its store to Meta's Muse](https://agentdots.org/incidents/amazon-blocks-muse/)

August 4, 2026
[Appeals court calls a shopping agent the user's tool](https://agentdots.org/incidents/ninth-circuit-agent-case/)
