Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

Salt Labs exploit gave attacker code execution inside Manus agent via one email

Salt Security disclosed a now-patched vulnerability in the Manus agentic AI platform where a single malicious email could grant code execution and access…

A single malicious email could have given an attacker code execution inside the Manus agentic AI platform and access to every credential the agent held, including cloud tokens, API keys, and access keys for connected services, Salt Security disclosed on October 11,3.

The vulnerability has been resolved and is no longer exploitable. Salt Labs, Salt Security's research arm, conducted the work earlier this year.

How the attack chain worked

Manus is a general-purpose agentic AI platform that independently carries out multi-step tasks such as research, data analysis, content creation, and software development, connecting to services including email, cloud storage, and code repositories. Salt Labs researchers found that Manus could interpret the contents of an incoming email as instructions, a class of vulnerability known as indirect prompt injection.

When researchers sent a test user an email containing a direct command, Manus flagged it. To bypass that detection, the researchers used an obscure JavaScript obfuscation technique to disguise the payload; Manus decoded and executed the hidden code. The attack chain required only two events: the malicious email arriving in the victim's inbox and the user asking Manus to check their messages. No stolen password, clicked link, or further victim action was needed.

Once the code ran, the researchers established a reverse shell within the Manus environment and located credentials and tokens associated with third-party services connected by the user. In a real-world scenario, those credentials could allow an adversary to reach connected email, cloud storage, and code repository accounts.

The platform generated a security warning only after the code had already executed. ANALYSIS That sequence illustrates a structural gap in agentic AI security: a control layer that detects malicious activity but fires too late to prevent an autonomous agent from completing the action before a human can intervene.

Disclosure and remediation

Salt Labs reported the issue to Manus but received no response. The researchers subsequently submitted the vulnerability through Meta's bug bounty program. Meta had been preparing to acquire Manus during this period, but the transaction did not proceed, and Meta and Manus remain separate. Later attempts by Salt Labs to reproduce the attack were unsuccessful, indicating remediation.

Yaniv Balmas is head of research at Salt Security. The company, founded in 2016, is backed by Sequoia Capital, S Capital, Tenaya Capital, Salesforce Ventures, Advent International, and other investors.

ANALYSIS The Manus finding puts a concrete proof-of-concept behind a risk that has so far been discussed mostly in theoretical terms: agentic systems that hold live credentials and act autonomously can turn a single indirect prompt injection into lateral access across an organization's cloud and code infrastructure. The gap between detection and prevention, where the agent completes the malicious action before any human review, is specific to autonomous execution and does not map neatly onto traditional application-security models.