The vulnerability relied on indirect prompt injection, a technique where the AI agent interprets email content as actionable instructions. While the Manus platform successfully flagged obvious malicious commands, researchers bypassed these safeguards by disguising their code with obscure JavaScript obfuscation. The system decoded and executed the hidden instructions, establishing a reverse shell that granted the attackers control over the agent's environment.
Crucially, the attack did not require the victim to click a link or provide a password. It triggered automatically once the user requested the agent to check their messages. Although the platform generated a security warning, it arrived only after the malicious code had already executed, highlighting a systemic failure where detection occurs too late to prevent damage. In an autonomous environment, the speed of machine execution renders traditional human-in-the-loop interventions largely ineffective.

Comments (0)
No comments yet. Be the first!