Researchers Reveal One Email Can Hijack AI Assistant Through Security Flaw
Researchers in security have shown that a single, maliciously crafted email can hijack the AI‑powered assistant Manus, enabling attackers to execute arbitrary code on its platform.
Promoted as a flexible agent that works with numerous third‑party services, Manus depends on prompt‑injection defenses to reject harmful commands. The team discovered that inserting a hidden JavaScript payload into the email body—obfuscated via the JSFuck method—allowed them to evade the filters and cause execution before the system raised an alert.
Their tactic concealed the malicious prompt within an otherwise ordinary email. After the message was parsed, Manus decoded the obfuscated script and interpreted the concealed commands as a valid request, leading to code execution on the host system. The vulnerability surfaced when the hidden prompts operated undetected for a short interval, exposing a shortcoming in the assistant’s handling of intricate, encoded inputs.
Analysts note that this incident highlights a wider issue: AI agents with broad access to external APIs and user information become lucrative targets when their input validation is weak. Such a compromise could lead to data theft, unauthorized operations on linked services, or even ransomware deployment, depending on the attacker’s goals.
After the report, Manus’s developers released a patch that strengthens scrutiny of incoming messages and enhances detection of JSFuck‑type obfuscation. The episode acts as a warning for the sector, spurring demands for stricter testing of prompt‑injection safeguards and increased openness about security practices for AI agents with extensive third‑party integrations.
Comments (0)
Be the first to comment.
Join the discussion