Manus · News date: · WATCH
Type: General Agent
A hidden email instruction could hijack Manus and steal connected accounts
Your move: Already fixed, but a reminder to review what's connected to your agent
Security researchers at Salt Labs found a way to hide an instruction inside an email using an obfuscated code trick, so Manus would carry it out before its safety filter could catch it. The hidden instruction let the researchers open a shell inside a victim's Manus session and pull out login credentials and tokens for any outside app connected to that account, such as Gmail, Drive, or GitHub. Salt Labs reported the flaw to Manus directly and got no response, but a report filed through Meta's bug bounty program, left over from Manus's earlier partnership with Meta, got the issue triaged, confirmed, and patched.
Why it matters
The specific hole is already closed, so there's nothing to update. But it's a real reminder that connecting accounts like email or code repositories to an agent widens what an attacker can reach if they trick the agent, so review which accounts you've connected to Manus and disconnect any you no longer need.
Source: Dark Reading ↗
Published by Agent Log. The summary reports the linked source; “Why it matters” and the verdict are Agent Log's interpretation.
More Manus updates →