Threat
Salt Labs Research: A Single Email Could Hijack an AI Agent and Reach a User's Connected Accounts
Publication date unknown · Discovered yahoo.com
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source research — one report is available.
Why it matters
The Manus attack demonstrates that agentic security controls may detect malicious activity yet fail to stop it, because an autonomous agent can complete the harmful action before any human can intervene.
Salt Labs published research showing the Manus agentic AI platform could be hijacked via a single malicious email using indirect prompt injection. Researchers disguised a command with JavaScript obfuscation to bypass guardrails; Manus decoded and executed it, enabling a reverse shell and access to credentials, cloud tokens, API keys, and keys for the user's connected services. The vulnerability was disclosed responsibly and has been resolved.