iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes. Salt Labs demonstrated that a specially crafted email could make Manus run attacker-controlled code when a user asked the AI agent to check Gmail. The reported Manus vulnerability has been resolved, but the incident shows why any agent that reads untrusted content and can use connected tools needs safeguards that block unsafe actions before they happen.
How the email attack worked
The email did not need to persuade the user to click a link or run an attachment. The dangerous step came when Manus read the message as part of a normal inbox task and treated hidden instructions inside it as directions to follow.
- The user connected Manus to Gmail and asked it to read, search, summarize, or reply to messages.
- An attacker sent an email containing hidden or obfuscated instructions.
- Manus retrieved the message through its Gmail workflow and interpreted its contents as executable instructions rather than untrusted data.
- Direct shell commands triggered a warning. Salt Labs bypassed that protection with JSFuck, an unusual way of obfuscating JavaScript.
- Manus invoked a Node.js runtime, ran attacker-controlled JavaScript, and then executed system commands in its sandbox.
- Salt Labs demonstrated a reverse-shell connection from the sandbox and found access to Gmail OAuth data.
In Salt Labs’ description, the victim’s only required action was asking Manus to check the inbox. That is why this is an indirect prompt-injection attack: the attacker puts instructions in content the agent later reads, rather than sending the instructions directly to the agent.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWhat the demonstration did—and did not—establish
Salt Labs demonstrated remote code execution inside a controlled sandbox and potential access to connected-account data. Depending on a user’s setup and permissions, connected Drive or GitHub credentials could also be exposed. The report does not establish that Manus customers were breached, that criminals used the flaw in the wild, or that customer data was stolen.
#1 Best Overall
Salt Labs said it disclosed the issue through Meta’s bug-bounty program and that it has been resolved. The available reporting does not give a CVE identifier or identify a particular fix version, so users should not infer an exact patched build from the disclosure.
Why this matters beyond Manus
The wider risk is architectural. An agent may receive a message, document, web page, or repository text from an outside party, then use tools to act on what it reads. If it fails to distinguish untrusted content from instructions, the content can try to steer the agent. If the agent can run code or use account credentials, a prompt-injection attempt can have consequences beyond an incorrect summary.
Rank #2
Obfuscation adds another complication: a filter that catches obvious commands may miss code disguised in an unusual form. In the Manus demonstration, the warning appeared only after the payload had run. Salt Labs’ conclusion was that “guardrails that inspect prompts and model behavior are necessary but not sufficient.” Detection needs to be paired with controls that prevent risky actions before execution.
The exposure is relevant because agents are being connected to sensitive services. Menlo figures for 2026, as quoted by TechRadar, put consumer agent access at 36% for email, 33% for web browsers, 31% for messaging apps, 29% for cloud storage, and 27% for calendars. The same figures put health apps at 23% and financial accounts at 20%, described as less common.
Rank #3
How to assess an AI agent connected to your accounts
For any agent that reads outside content or can use connected tools, check the controls that determine whether an injected instruction can become an action. A warning after execution is not an adequate substitute for an execution boundary.
Quick Recap
Best Value
Rank #4
| What to check | Safer design | Why it matters |
|---|---|---|
| Separation of content and instructions | External emails, documents, and web pages are treated as untrusted data, not as authority to change the agent’s task or rules. | Prevents content written by an attacker from being treated like a trusted instruction. |
| Code execution | Code cannot run automatically from content the agent reads; execution is blocked or requires approval before it starts. | A post-execution warning cannot undo code that has already run. |
| Sandbox and network access | Execution is isolated, and outbound network access is restricted to what the task requires. | Limits the ability of malicious code to reach outside the sandbox or communicate with an attacker. |
| Tool permissions and credentials | Grant only the necessary account scopes and tools, use separate credentials where possible, and avoid broad access by default. | Limits what an agent can read or change if it is manipulated. |
| Outbound and destructive actions | Require a human confirmation before sending messages, changing records, deleting files, or making other consequential changes. | Stops an agent from turning an untrusted instruction into an irreversible or externally visible action without review. |
| Monitoring and audit records | Keep logs of tool calls and code execution, and alert on unexpected access or network activity. | Makes suspicious behavior easier to detect and investigate. |
Practical steps for users
- Review which accounts and permissions you have connected to an agent. Remove integrations and scopes you do not need.
- Use read-only access where it is available and sufficient for the task.
- Require confirmation for sending email, sharing files, changing repository contents, or deleting data.
- Do not treat an agent’s warning or security label as proof that a requested action was blocked; check whether the control acts before execution.
- For Manus specifically, Salt Labs reports that this issue was resolved. The report does not specify a fix build, so consult Manus’s current security guidance if you need confirmation for a particular deployment.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

