Salt Labs shows a single email could hijack Manus and reach connected accounts
Salt Security’s Salt Labs said Thursday that a malicious email could hijack the Manus agentic AI platform via indirect prompt injection, executing before Manus’s own warning fired, and exposing credentials for connected services; the issue was disclosed and is no longer exploitable.
Agent guardrails that warn after the tool already ran are theater. Salt’s write-up is the blunt lesson for anyone wiring agents to email and cloud tokens: detection without pre-action control is not a defense when the agent moves faster than a human can click Cancel.
On Thursday, 1 October 2026, Salt Security published Salt Labs research on the Manus platform. The press release is titled “Salt Labs Research: A Single Email Could Hijack an AI Agent and Reach a User’s Connected Accounts.” The dateline is Palo Alto, Calif., October 1, 2026. The company page does not print an hour. PR Newswire carries the same announcement and stamps Oct. 01, 2026, 08:00 ET. Salt says a single malicious email could have hijacked the Manus agentic AI platform and exposed accounts the user had connected. The vulnerability was disclosed responsibly and has since been resolved. Salt says it is no longer exploitable. Those lines are Salt Security’s.
What Manus is, in Salt’s words. Manus is a general-purpose agentic AI platform. Agentic means the software can carry out a series of steps on its own, rather than only answering a question. Salt says it can independently do multi-step work, such as research, analyzing data, creating content, and developing software. Individuals and business teams use it to automate work by giving ordinary-language instructions. Those lines are Salt’s. The release describes who uses it. It does not print a user count.
The problem Salt says the research is about. The line under the headline says research into Manus shows that agentic security controls can detect an attack and still fail to stop it before an autonomous system acts. A control, here, is a safety check. Autonomous means the agent acts without waiting for a person. Salt says a check may notice malicious activity and still fail to prevent it, because the agent can finish the action before a human has a chance to step in. Those lines are Salt’s.
What the agent can reach. Manus can connect to services including email, cloud storage, and code repositories. A code repository is the place a team keeps its software files. Salt says that connectivity is central to why the product is useful, and that it also widens the attack surface. An attack surface is the set of places an attacker can try to get in. Those lines are Salt’s.
Indirect prompt injection. Salt Labs found that Manus could treat the text of an incoming email as instructions. The release calls that indirect prompt injection. A prompt is the instruction given to the model. Indirect means the instruction did not come from the person at the keyboard. It was sitting in something the agent was asked to read, in this case an email. When researchers sent a test user an email that contained an obvious malicious command, Manus flagged it. Salt says that showed the guardrails could recognize an obvious malicious instruction. A guardrail is a limit meant to catch unsafe behavior. Those lines are Salt’s. The release does not quote the wording of that obvious command.
The disguise that got through. Salt says the researchers then used an obscure JavaScript obfuscation technique to hide the command, one of several methods meant to evade detection. Obfuscation means rewriting an instruction so a filter does not recognize it, while a computer still can. JavaScript is a programming language used in browsers and on servers. Salt Labs’ research post, published the same day, names that disguise JSFuck. JSFuck is a way of writing JavaScript with only a small set of punctuation marks, so a check looking for ordinary words can miss it. Salt says Manus decoded the hidden code and ran it. The platform generated a security warning only after the code had already run. The research post says the same thing: Manus’s own guardrail detected the attack, but only after the code had run, and on a system that acts on its own no person sits between the alert and the action. Those outcome lines are Salt’s.
What the researchers reached after the code ran. The press release says they established a reverse shell inside the environment and found credentials and tokens for third-party services the user had connected. A reverse shell is a connection back to the researcher, so commands can run on the machine the agent was using. A credential is a secret that proves identity. A token is a temporary pass a service accepts instead of asking for the password again. The research post is more specific about what was in that environment. It says the environment could reach the Gmail connection, including the OAuth token for the test user. OAuth, here, is the permission the user had already granted so Manus could open their mail. The post also says that when a user had connected other services, such as Google Drive or GitHub, related credentials and access tokens were present as well. The press release says a real attack could then reach the connected email, cloud storage, and code-repository accounts. Those lines are Salt’s. They describe what the lab found after the code ran.
What a real attack would have needed. Salt says the chain required only two events: the malicious email arriving in the inbox, and the user asking Manus to check their messages. It did not require a stolen password, a clicked link, or any further action by the person. The PR Newswire caption on the still says the user asked only to check their email, and that in the same moment one malicious email gave the attacker code execution inside the Manus agent’s environment, plus the credentials it held: cloud tokens, API keys, and access keys for the connected services. Code execution means the attacker’s code actually ran. An API key is a secret a program needs before it can call another service. Those lines are the caption’s. They match the release.
Why Salt says the lesson is bigger than this one flaw. The release says the significance extends beyond the specific vulnerability, which has since been addressed. Detection alone may give little protection when an autonomous system can act before an alert reaches a person. In an ordinary setup, an alert can give someone time to look and step in. With an autonomous agent, the action and its consequences may already have happened. A control that identifies malicious behavior only after execution has failed to prevent the attack. Salt says guardrails that inspect prompts and model behavior remain part of the design, and that they cannot provide complete protection on their own. Controls also have to govern and monitor what an agent does across the tools, APIs, data, and systems it can reach. An API is a connection one program uses to ask another program to do something. Those lines are Salt’s.
What the head of research said. Yaniv Balmas, head of research at Salt Security, is quoted in the release. “The agentic domain is relatively new, and the industry is still learning how to use it correctly, and so are attackers,” he said. He said guardrails are an important part of any agentic system that handles untrusted input, but they are often simply not enough. Untrusted input is text the company did not write, such as an email from outside. He said anyone designing an agentic system should build robust, layered defenses rather than trusting guardrails to provide all the protection, “exactly as we learned to do with traditional services.” He said that as agentic adoption grows, he has no doubt this will become one of the most common attack vectors. An attack vector is a way in. That quotation is his, in the release.
How it was disclosed. Salt says the research was conducted earlier this year. Salt Labs reported the issue to Manus and received no response. The researchers then submitted the vulnerability through Meta’s bug bounty program. A bug bounty is a program that takes security reports through an official channel. Meta triaged the report, confirmed it, and addressed it. Triaged means Meta took the report in and put it in line for a fix. Later attempts by Salt Labs to reproduce the attack were unsuccessful, which Salt says indicates the issue had been remediated. Remediated means fixed. Salt also says Meta had been preparing to acquire Manus during this period. The transaction did not proceed, and the companies remain separate. Those lines are Salt’s. Salt’s own words are that the flaw has been resolved and is no longer exploitable.
The picture is the Salt Labs proof-of-concept still that runs with the release. A dark Manus workspace fills the frame. On the left is a task list. In the center is an email view, with an Inbox and a message from a sender labeled Researcher. The subject line reads Meeting follow-up. On the right, the agent panel shows a block of punctuation-only code, then a line that a connection was established. A red warning sits over that panel and says potential malicious activity was detected. A Salt Labs mark is at the lower right. The frame does not print a calendar date. It is the proof-of-concept still. It is not a photograph of a person.
In plain terms, Salt Labs said on Thursday that a single malicious email could hijack Manus, an agent that can connect to email, cloud storage, and code repositories, and could expose credentials for those connected accounts. An obvious bad command was flagged. A disguised command, written in the punctuation-only style the lab calls JSFuck, was decoded and run, and the security warning came only after the code had already run. The lab says the researchers then had a reverse shell and could see tokens for connected services, including mail and, where the user had connected them, services such as Google Drive and GitHub. A real attack, Salt says, needed only the email’s arrival and the user asking Manus to check messages. No stolen password, and no clicked link. Salt reported it to Manus, got no answer, and sent it through Meta’s bug bounty. Meta confirmed it and fixed it. Salt says later attempts to repeat the attack failed, and that the issue is no longer exploitable. Meta had been preparing to buy Manus. That deal did not happen, and the companies are still separate.
