chiprook
← Security
SecurityOctober 5, 2026, 10:06

Salt Labs: JSFuck Obfuscation Bypassed Manus AI Agent Guardrails

Salt Labs researchers reported that a prompt injection hidden in JSFuck-encoded punctuation bypassed Manus AI's guardrails. The agent decoded and executed the instructions before its own security warnings fired, reportedly yielding a reverse shell and credentials for connected third-party apps. The issue was disclosed and patched.

Salt Labs: JSFuck Obfuscation Bypassed Manus AI Agent Guardrails
#Manus#SaltLabs
Read next
Security

Prompt-injection bug found in $4B agentic AI app Manus

Security

Aegis-DevOps 0.3.0 compiles AI agent guardrails into AWS SCPs

Security

Gigamon: 56% of Australian CISOs deploy AI security guardrails

AI

Manus regains independence, launches Manus 2.0 and Cue AI agent