Threat

Salt Labs Research: A Single Email Could Hijack an AI Agent and Reach a User's Connected Accounts

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026yahoo.comobserved

Single-source research — one report is available.

Why it matters

The Manus attack demonstrates that agentic security controls may detect malicious activity yet fail to stop it, because an autonomous agent can complete the harmful action before any human can intervene.

Salt Labs published research showing the Manus agentic AI platform could be hijacked via a single malicious email using indirect prompt injection. Researchers disguised a command with JavaScript obfuscation to bypass guardrails; Manus decoded and executed it, enabling a reverse shell and access to credentials, cloud tokens, API keys, and keys for the user's connected services. The vulnerability was disclosed responsibly and has been resolved.