Skip to content

Security1 publisher2 min readPublished

Manus agent ran attacker JavaScript from an email it had already flagged as suspicious

Salt Labs got the Manus AI agent to run attacker JavaScript server-side with a JSFuck-encoded prompt hidden in an email the agent had flagged. Detection fired and the code still ran, so agents connected to outside services need limits on what their code can reach.

The Watch · Security desk

Illustration accompanying Manus agent ran attacker JavaScript from an email it had already flagged as suspicious
Generated illustration

What happened

  • SC World describes the result as a security boundary violation in which untrusted email content was turned into executable code.
  • SC World's brief argues prompt inspection is necessary but not sufficient, and that controls must cover the actions an agent takes across its tools, APIs and systems.
  • Tech Radar first disclosed the research, and SC World's brief summarizes that report.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Agents that read inbound email take input from outside senders, and here a single message was enough to get attacker code running in the vendor's server-side environment.
  • decision Teams deploying agents with third-party access have to decide what agent-run code may reach on the host, because input screening that recognized this attack did not stop it.
  • precedent SC World expects attack methods beyond JSFuck, so a fix aimed at one encoding would not stop the next encoding from being flagged and still executed.

Manus's protections fired first. They flagged the email carrying Salt Labs' hidden prompt as suspicious [3][4]. According to SC World, the agent then decoded the JSFuck payload and ran it as arbitrary JavaScript in its server-side environment before its security mechanisms could fully intervene [5]. The agent did the decoding itself. It turned the obfuscated text back into working code and then executed it [5].

The order of events changes the diagnosis. When a filter misses an encoding, a better signature can fix it. This filter recognized the input, and the payload still ran on the server [4][5].

SC World's brief names the researcher, the agent, the encoding and the delivery method [1][2][3]. It leaves out disclosure and patch dates, what the server-side environment could reach, any use of the technique outside the research, and any threat actor or campaign. On that record, this is a researcher finding that was handled through Meta's bug bounty program [7].

The exposure that remains after the patch applies to agents of this kind generally. SC World places the case within the ongoing risk from AI agents granted broad access to third-party services [11]. It also expects creative attack methods beyond JSFuck [10]. A rule written for JSFuck covers this payload only, and with a different encoding the filter could again flag the email while the agent still ran the code [4][10].

In this chain, the action that mattered was the agent executing server-side JavaScript it had decoded from untrusted mail [5]. The control that would have contained it is a limit on what agent-run code can reach, enforced whether or not the input filter raises a flag. The brief's own remedy, monitoring and controlling what the agent does, applies at that same point [9].

What to watch

  • Salt Labs or Meta publishing dates, the permissions of the Manus server-side environment, and what the executed JavaScript could reach.
  • Whether the same encode-then-decode approach succeeds against other agents that process email or other third-party content.
  • Any report of the technique being used against Manus users outside the research.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories