Salt Labs bypassed Manus guardrails with JSFuck email injection
Salt Labs researchers bypassed Manus prompt-injection protections by hiding a JSFuck-encoded payload in an email, which the AI agent decoded and executed in its runtime. The flaw was reported via Meta's bug bounty program and has been patched.
- JSFuck-encoded prompt in an email led to arbitrary JavaScript execution
- Manus flagged the threat but notified the owner only after code ran
- The flaw was disclosed via Meta's bug bounty and is now fixed
- 36% of consumers give AI agents email access, 33% browser access
Read next
Security