Salt Security published research showing a critical vulnerability in the Manus agentic AI platform that could have let a single malicious email hijack the system and expose user-connected accounts. The vulnerability has since been addressed, but it highlights fundamental security challenges enterprises face when deploying autonomous AI agents. Manus is a general-purpose agentic AI platform that lets users automate multi-step tasks, including research, data analysis, content creation, and software development, through natural-language instructions. Manus' connectivity to services including email, cloud storage and code repositories represents both a functional strength and a significant security consideration.[1]
Salt Labs researchers identified that Manus could interpret email content as direct instructions, a technique known as indirect prompt injection. When researchers transmitted a test user an email containing an explicit command, Manus's security guardrails detected and flagged the obvious malicious instruction. The researchers then obscured the command using a JavaScript obfuscation technique designed to evade detection. Manus decoded and executed the concealed code. Critically, although the platform generated a security warning, it issued the alert only after the code had already executed.
Researchers next established a reverse shell within the environment and identified credentials and tokens associated with third-party services connected by the user. In a real attack scenario, an adversary could have used this access to reach connected email, cloud storage, and code repository accounts.
The research reveals a fundamental security paradox within autonomous systems. Traditional security alerts provide individuals with time to investigate and intervene before consequences materialize. With autonomous agents, actions and their consequences may occur before humans can intervene. Manus's security guardrail functioned as designed, detecting malicious activity, yet it provided no practical protection because it detected the activity only after execution. A control that identifies malicious behavior only after an agent has acted fundamentally fails to prevent the attack.
This distinction has direct implications for enterprises deploying AI agents. Guardrails inspecting prompts and model behavior remain important architectural components but cannot provide comprehensive protection independently.
In an expert comment, Yaniv Balmas, Head of Research at Salt Security, remarked on the research significance: "The agentic domain is relatively new, and the industry is still learning how to use it correctly, and so are attackers. Guardrails are an important part of any agentic system that handles untrusted input, but they are often simply not enough." Balmas emphasized the necessity for comprehensive security architecture: "Anyone designing an agentic system should build robust, layered defenses rather than trusting guardrails to provide all the protection, exactly as we learned to do with traditional services. As agentic adoption grows, I have no doubt this will become one of the most common attack vectors we see."
Salt Labs conducted research earlier this year and reported the issue to Manus but received no response. The researchers subsequently submitted the vulnerability through Meta's bug bounty program. Meta confirmed, triaged, and addressed the issue. Subsequent reproduction attempts by Salt Labs proved unsuccessful, confirming remediation. Meta had been acquiring Manus during this period; the transaction did not proceed, and the companies remained separate.
This article used AI to craft the contents and is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC). For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929
[1] https://www.cybersecurityintelligence.com/blog/single-malicious-email-could-hijack-agentic-ai-platform-9794.html
Comments