Salt Labs: JSFuck Obfuscation Bypassed Manus AI Agent Guardrails
Salt Labs researchers reported that a prompt injection hidden in JSFuck-encoded punctuation bypassed Manus AI's guardrails. The agent decoded and executed the instructions before its own security warnings fired, reportedly yielding a reverse shell and credentials for connected third-party apps. The issue was disclosed and patched.
- Plaintext injections were blocked; the JSFuck version got through
- Researchers reportedly reached a reverse shell and third-party tokens
- JSFuck encodes any script using only [ ] ( ) ! +
- The flaw was disclosed and reportedly patched
Read next
Security