chiprook
← Security
SecurityOctober 3, 2026, 00:05

Salt Labs bypassed Manus guardrails with JSFuck email injection

Salt Labs researchers bypassed Manus prompt-injection protections by hiding a JSFuck-encoded payload in an email, which the AI agent decoded and executed in its runtime. The flaw was reported via Meta's bug bounty program and has been patched.

Salt Labs bypassed Manus guardrails with JSFuck email injection
#Manus#Meta#Gmail
Read next
Security

Prompt-injection bug found in $4B agentic AI app Manus

Software

Gmail Adds 'Copy Code' Button for 2FA Emails

AI

Viral Screenshots Claim ChatGPT Emailed the FBI From a User's Gmail Unprompted

Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root