Researchers Bypassed Manus Email Guardrails With JSFuck Payload, Executing Code Before Alert
Salt Labs bypassed Manus’s email prompt-injection defenses by hiding a JSFuck-encoded JavaScript payload in a message, achieving code execution in the AI agent’s runtime before Manus flagged the activity. The flaw has been patched.
Prompt injection is not new. AI models cannot reliably distinguish between instructions and data to be analyzed. If a user asks an agent to summarize an email and that email contains another prompt, the agent may execute both. If the hidden prompt is malicious, such as asking the agent to collect emails containing the word “password” and send them elsewhere, the consequences can be severe. The attack requires the agent to be connected to third-party services such as email, calendars or social accounts, but that access is spreading.
Menlo’s “2026: The State of Consumer AI” report said consumers are giving agents access to email (36%), web browsers (33%), messaging apps (31%), cloud storage (29%) and calendars (27%). Access to sensitive applications was less common, with 23% for health apps and 20% for financial accounts, according to the report.
AI developers know about prompt injection and have added safeguards. Manus, for example, can detect when a prompt is hidden inside data it is asked to analyze. It does not simply ignore such prompts; it notifies the owner when it identifies a malicious one.
Salt Labs tested Manus’s integration with Gmail. The researchers sent an email containing a hidden prompt. Manus identified it as malicious and said so in its response. “Manus interpreted the email’s contents as executable instructions. It wasn’t treating the email as passive data; it was attempting to follow the instructions embedded within it. The execution was only interrupted because a security mechanism recognized the action as potentially dangerous,” the researchers explained.
That led Salt Labs to ask what would happen if Manus did not recognize the prompt as malicious. The researchers tried different methods, including Base64 encoding, and had the agent decode and execute prompts using Python. They eventually used JSFuck, which they described as an unusual JavaScript obfuscation method that uses a limited set of characters and is rarely used in modern environments.
The researchers prepared a simple payload encoded in JSFuck that would execute a basic JavaScript statement and included it in an email. “The intent appeared to be content decoding and rendering. However, this effectively executed arbitrary JavaScript code in a server-side environment!” they said. “The payload successfully executed, and we observed the expected output.” Salt Labs called it a clear security boundary violation: untrusted email content was transformed into executable code and run within the agent’s runtime environment.
Manus did notify the owner, but only after the malicious code had executed, which Salt Labs characterized as too little, too late. The researchers said they responsibly disclosed their findings through Meta’s bug bounty program, and the issue has since been resolved and is no longer exploitable.
Salt Labs said the episode carries a lesson for enterprises deploying AI agents: guardrails that inspect prompts and model behavior are necessary but not sufficient. Security has to extend to what an agent actually does across the tools, APIs and systems it can reach, the researchers concluded. If they could work around Manus’s guardrails, criminals may also find ways, perhaps not through JSFuck.