Security researchers recently identified a vulnerability in the agentic AI platform Manus, which has since been patched. This vulnerability had the potential to allow attackers to hijack an AI agent through a single malicious email, subsequently enabling access to a user’s connected accounts. The findings were disclosed by researchers at Salt Labs, the research division of Salt Security.
Manus is a versatile agentic AI platform designed to autonomously manage a variety of tasks. These tasks range from conducting research and data analysis to creating content and developing software. One of its significant features is the ability to link with external services, including email, cloud storage, and code repositories, enhancing its multifunctionality. However, this connectivity paved the way for a new type of attack known as an indirect prompt injection attack, which can mislead the AI into interpreting malicious instructions from external content as legitimate commands.
During the investigation, researchers at Salt Labs initially tested Manus by sending an email containing a direct malicious command. Remarkably, Manus was able to detect this attempt and flagged the message, demonstrating that its existing security measures could recognize this kind of attack. However, the researchers subsequently explored more sophisticated techniques, eventually disguising the malicious command using a complex JavaScript obfuscation method. This led to a crucial finding: Manus decoded and executed the concealed instructions, although it did issue a security warning post-execution. This warning, however, came too late, as the command had already been acted upon, revealing a lapse in the system’s protective measures.
The researchers managed to establish a reverse shell within the Manus environment, allowing them to locate sensitive credentials and tokens tied to various connected third-party services from the test account. Salt Labs articulated that the real-world exploitation of this vulnerability could enable attackers to gain unauthorized access to a victim’s email, cloud storage, and code repositories. Alarmingly, the attack required no user intervention beyond the arrival of the malicious email in the victim’s inbox and an innocuous request for Manus to check new messages.
Notably, this vulnerability was responsibly disclosed, which allowed for immediate remediation, meaning that the exploit described by Salt Labs is no longer feasible. However, the implications of these findings extend far beyond this particular incident. The researchers contend that they highlight a more pervasive security issue facing agentic AI systems. The difficulty of detecting malicious activity can be exacerbated by the fact that once an autonomous agent has executed an action, human intermediaries may find it challenging to intervene effectively.
As businesses increasingly grant AI agents access to critical applications, APIs, and sensitive information, Salt Labs emphasized the necessity for security controls that extend beyond merely overseeing the prompts and behaviors of AI models. Organizations must consider implementing comprehensive governance frameworks to manage the actions agents are allowed to undertake across interconnected systems.
Yaniv Balmas, the Head of Research at Salt Security, stated, “The agentic domain is relatively new, and the industry is still learning how to use it correctly, just as attackers are adapting to exploit it.” He underscored the importance of implementing robust and layered defenses rather than overly relying on guardrails, especially when dealing with untrusted input. This mindset should parallel the lessons learned from securing traditional services.
Balmas further cautioned that as the adoption of agentic AI escalates, the frequency and sophistication of attacks targeting these systems are likely to increase. The dynamic and evolving nature of the threat landscape necessitates that organizations remain vigilant and proactive in enhancing their security frameworks to mitigate potential vulnerabilities.
In conclusion, while the immediate threat posed by the Manus vulnerability has been neutralized, it serves as a stark reminder of the broader challenges that come with integrating AI into operational frameworks. The findings from Salt Labs advocate for a comprehensive approach to security that prioritizes not just prevention but also accountability for actions taken by autonomous agents in interconnected environments.
The implications of these insights resonate deeply within the tech industry, urging organizations to adopt a more cautious and informed perspective on the use of agentic AI systems. As the landscape continues to evolve, the call for enhanced security measures becomes increasingly critical. The potential for such vulnerabilities necessitates ongoing dialogue and vigilance among stakeholders to ensure the safe deployment of AI technology.

