Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
HazardAI acted on its ownSeverity N: legal or test findingReported: press reporting only

Salt Labs bypassed Manus AI agent's prompt-injection guardrails to run code hidden in an email

Security researchers from Salt Labs found that a hidden prompt in an email, obfuscated with the JSFuck JavaScript technique, made the Manus AI agent execute arbitrary JavaScript in its server-side runtime through its Gmail integration. Manus notified the owner only after the code had run. The researchers disclosed the flaw through Meta's bug bounty program and said it has been resolved and is no longer exploitable.

What the AI did

The Manus AI agent, connected to a user's Gmail, read an email containing a hidden instruction disguised with a coding trick called JSFuck, which scrambles code into unreadable symbols. It then ran that content as computer code on its own servers, and told the account owner only after the code had already run.

First reported October 2, 2026 · Added to the register October 7, 2026 · 1 source

Model
Manus
When it happened
Not stated in the sources
First reported
October 2, 2026

What this means for you

Could this affect you?

Possibly, if you connect AI agents to your email or other services

Users who connected the Manus AI agent to Gmail were exposed, before the fix, to emails that could make the agent run hidden code.

What to check

  • Limit the tools and data your AI agents can reach.
  • Treat incoming email content as untrusted input for any AI agent.
  • Monitor what agents actually do across connected services.
  • Avoid relying on filters that only inspect the instructions given to an agent.
Every fact and its source (6)
  1. ResearchersSalt Labs
    “Security researchers from Salt Labs have found a way around the guardrails”[1]
  2. Integration testedManus Gmail integration
    “Salt Labs tested Manus’ integration with Gmail.”[1]
  3. Bypass techniqueJSFuck obfuscation
    “Eventually they struck gold, in the form of - JSFuck.”[1]
  4. FindingUntrusted email content executed as code in agent runtime
    “untrusted email content was transformed into executable code and run within the agent’s runtime environment”[1]
  5. Disclosure channelMeta's bug bounty program
    “Salt Labs said they responsibly disclosed their findings through Meta’s bug bounty program”[1]
  6. StatusFixed, no longer exploitable
    “has since been resolved as is no longer exploitable.”[1]

Sources

  1. This popular AI agent could be hacked by a single email — with potentially disastrous consequences
    techradar.com · October 2, 2026

How this record is classified. Severity N: a legal action or test finding, not a harm. OECD level: hazard, an event that could plausibly have led to harm. Evidence: Reported, meaning press reporting only.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

Promotional banner for the Pentest Readiness checklist download