Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Popular AI agent Manus could be hacked with a single email, researchers show

Security researchers at Salt Labs bypassed Manus's prompt-injection defenses by hiding a JSFuck-obfuscated instruction inside an email, achieving arbitrary JavaScript code execution in the agent's server-side runtime. The flaw has since been patched, but the team warns that agents with broad third-party access remain exposed to similar attacks.

Published

Security researchers at Salt Labs say they found a way around the guardrails protecting Manus, a popular AI agent. By planting a hidden prompt inside an ordinary email, they got the agent to execute arbitrary JavaScript on the server side. TechRadar reports the flaw has since been fixed.

Prompt injection has plagued AI agents since their earliest days. The root problem is that models cannot reliably separate instructions from the data they are asked to process: ask an agent to summarize an email, and a second prompt buried in that email may run alongside your own request.

Salt Labs tested Manus's integration with Gmail. They sent an email containing a concealed prompt; Manus flagged the content as executable and warned its owner, but it still tried to act on the instructions, stopping only when a safety mechanism detected the danger.

That raised a sharper question: what if the agent never recognized the prompt as malicious? The team tried Base64 encoding and having the agent decode and run payloads with Python, and eventually found success with JSFuck, an unusual JavaScript obfuscation method that uses a very limited character set and is rarely seen in modern environments.

They embedded a simple JSFuck-encoded payload that would execute a basic JavaScript statement. “The intent appeared to be content decoding and rendering. However, this effectively executed arbitrary JavaScript code in a server-side environment,” the researchers wrote. The payload ran and produced the expected output. Untrusted email content had become executable code, running inside the agent's runtime. Manus did notify the owner — but only after the code had already executed.

Salt Labs says it disclosed the issue responsibly through a bug bounty program, and that it has since been resolved and is no longer exploitable. But the broader lesson, the team argues, is that if researchers can get around Manus's guardrails, criminals can too — perhaps not with JSFuck, but human creativity has no bounds.

The attack surface is growing. Menlo's 2026 State of Consumer AI report, cited by TechRadar, found that consumers have already given agents access to their email (36%), web browsers (33%), messaging apps (31%), cloud storage (29%) and calendars (27%), with health apps (23%) and financial accounts (20%) increasingly in the mix.

Salt Labs's warning is aimed at every enterprise deploying agents: guardrails that inspect prompts and model behavior are necessary but not sufficient, and security has to cover what an agent actually does across the tools, APIs and systems it can reach. As long as a single injection can escalate into code execution, handing an agent the keys to your inbox remains a calculated risk.

Why it matters

Agents wired into email, calendars and cloud storage can turn a routine prompt injection into real code execution once their guardrails fail. Enterprises need to audit what an agent does across its connected tools, not just what it reads.

ManusAI AgentSecurity
Back to realtime news

Nearby Updates

All