Meta's Muse AI agent operates in tiny AMD EPYC CPU sandboxes

Meta's Muse AI agent runs in CPU-only Ubuntu sandboxes hosted on AMD EPYC 9D25 processors, with each user receiving two cores and 8GB of memory. Users found that Muse can relay some terminal commands and reveal host details, raising concerns about potentially unsafe actions such as setting up SSH access. Meta separates inference onto GPU servers, and Muse has reportedly surpassed 500,000 daily active users.
Meta's Muse agent reportedly operates in Ubuntu 24.04 environments that lack GPUs, hosted on AMD EPYC 9D25 "Turin" processors. Each user receives two cores and 8GB RAM, while model inference occurs on separate GPU servers. The 9D25 is a high-density part with 126 cores and 254 threads; two cores are typically disabled or reserved.
Blogger Evan Hoffman and analyst Tae Kim found Muse would execute some basic Ubuntu commands and return host details. It also reportedly offered to configure SSH access to its private VM, though a kernel-buffer query failed on permissions. Rough estimates suggest 500,000 daily users could require about 2,000 dual-socket trays.
The exposure of host details and command execution may affect Meta, Muse users, and cloud operators. If sandboxes can relay terminal actions or enable SSH, attackers could potentially pivot beyond intended limits, though observed permission failures suggest some safeguards. As agent use grows, users may need clearer boundaries and monitoring. Enterprises evaluating similar CPU-only sandbox designs could reassess isolation, while daily users may face privacy or security risks if misconfigurations occur.