AI agents vulnerable to prompt injection attacks via email, researchers find
Security researchers at Salt Labs have exposed a critical vulnerability in Manus AI agents, bypassing their prompt-injection protections using JSFuck obfuscation. The flaw allowed arbitrary code execution via a single email, highlighting risks posed by AI agents with broad access to third-party services like Gmail and cloud storage. While the issue has been patched, the incident raises concerns about the security of AI integrations in sensitive applications.
Editor, Lazyfounder

Security researchers at Salt Labs have exposed a critical vulnerability in Manus AI agents, bypassing their prompt-injection protections using JSFuck obfuscation. The flaw allowed arbitrary code execution via a single email, highlighting risks posed by AI agents with broad access to third-party services like Gmail and cloud storage. While the issue has been patched, the incident raises concerns about the security of AI integrations in sensitive applications.
30 SEC SUMMARY
- Salt Labs researchers bypassed Manus AI agent’s prompt-injection protections using JSFuck obfuscation, enabling arbitrary code execution via a single email.
- The vulnerability, now patched, allowed attackers to exploit AI agents with access to third-party services like Gmail.
- Manus AI agents detected malicious prompts but only alerted owners after execution, highlighting a critical gap in real-time protection.
- Prompt injection attacks exploit AI’s inability to distinguish between commands and data, posing risks for AI agents with broad permissions.
- AI agents are increasingly granted access to sensitive services, including email, cloud storage, and financial accounts.
TABLE OF CONTENTS
- How the attack worked
- Prompt injection risks in AI agents
- Response and patch
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Salt Labs researchers bypassed Manus AI’s prompt-injection protections using JSFuck obfuscation, enabling arbitrary code execution via a single email.
- Manus AI agents detected malicious prompts but only alerted owners after execution, not in real time.
- The vulnerability was patched after disclosure through Meta’s bug bounty program.
- AI agents are increasingly granted access to sensitive services like email, cloud storage, and financial accounts.
- Prompt injection attacks exploit AI’s inability to distinguish between commands and data.
How the attack worked
In a test conducted by cybersecurity researchers at Salt Labs, the Manus AI agent’s integration with Gmail was compromised by sending an email containing a hidden prompt obfuscated using JSFuck, an unusual JavaScript obfuscation method. According to TechRadar, the technique uses a limited set of characters and is rarely employed in modern environments, making it harder to detect.
The Manus AI agent, which had access to Gmail, identified the hidden prompt as malicious but only notified the owner after executing the arbitrary JavaScript code. This delayed response highlights a critical gap in real-time protection for AI agents with broad third-party permissions.
Prompt injection risks in AI agents
Prompt injection attacks occur when AI agents execute hidden commands embedded in data—such as emails, documents, or messages—without distinguishing them from legitimate prompts. This vulnerability is inherent to large language models (LLMs), which process inputs as instructions regardless of their origin.
The attack demonstrated by Salt Labs could only succeed if the AI agent had access to third-party services like email, calendars, or cloud storage. These integrations, while useful, create new attack surfaces that bad actors can exploit.
Data from the research indicates that consumers increasingly grant AI agents access to sensitive applications: 36% for email, 33% for web browsers, 31% for messaging apps, 29% for cloud storage, and 27% for calendars. Less common but still significant are permissions for health apps (23%) and financial accounts (20%).
Response and patch
Salt Labs disclosed their findings through Meta’s bug bounty program, which facilitated the patching of the vulnerability in the Manus AI agent. According to TechRadar, the issue has since been resolved, though the incident raises broader questions about the security of AI agents with extensive third-party access.
The delayed notification of malicious activity—only after execution—underscores the need for real-time intervention mechanisms in AI systems. While Manus could detect the threat, its inability to block it preemptively left users exposed.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
This research underscores a fundamental tension in AI agent design: utility versus security. Founders building or integrating AI agents must recognize that every third-party service—email, cloud storage, calendars—becomes a potential attack surface. The Manus case shows that even if an agent detects malicious prompts, post-execution alerts are too late. Real-time sandboxing, strict permission scoping, and rigorous input validation are no longer optional; they’re table stakes.
For operators, the takeaway is clear: audit not just what your AI agents can do, but what they could be tricked into doing. The broader risk here isn’t just a single vulnerability—it’s the assumption that AI agents can safely handle untrusted data at scale. That assumption is now in question.
Key takeaways
- AI agents with broad third-party access—like email or cloud storage—are prime targets for prompt injection attacks.
- JSFuck obfuscation, though rare, can bypass AI security measures, enabling arbitrary code execution.
- Current AI agents often lack real-time intervention capabilities, relying instead on post-execution alerts.
- Prompt injection attacks exploit the inability of AI to distinguish between commands and data, a core vulnerability in LLM-based systems.
- Over a third of consumers grant AI agents access to sensitive applications, increasing the stakes for securing these integrations.
FAQ
What is JSFuck obfuscation?
JSFuck is an unconventional method of obfuscating JavaScript code using a limited set of characters. It is rarely used in modern environments, making it difficult for security systems to detect.
How do prompt injection attacks work?
Prompt injection attacks exploit an AI agent’s inability to distinguish between legitimate commands and hidden prompts embedded in data. When an AI processes the data as instructions, it can execute unintended actions.
What third-party services are most at risk?
AI agents with access to email, cloud storage, calendars, messaging apps, and financial accounts are particularly vulnerable. These services often handle sensitive data, creating attractive targets for attackers.
Was the Manus AI vulnerability fixed?
Yes. Salt Labs disclosed the issue through Meta’s bug bounty program, and Manus has since patched the vulnerability.
How can founders protect their AI agents from similar attacks?
Founders should implement real-time sandboxing, limit third-party permissions to only what is necessary, and validate all inputs rigorously. Regular security audits and penetration testing can also help identify and mitigate risks.
Related on Lazyfounder
Sources
- TechRadar · 2026-10-02
This popular AI agent could be hacked by a single email — with potentially disastrous consequences
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


