Salt Labs finds prompt-injection flaw in Manus AI agent enabling remote code execution
Security researchers at Salt Labs privately disclosed to Dark Reading a prompt-injection vulnerability in the AI agent platform Manus that let them execute remote code inside another user's Manus environment. The flaw could be exploited to manipulate not just Manus itself but any third-party services, such as email or other connected apps, that a victim had linked to it. Manus, which drew 2 million waitlist signups within a week of its March 2025 launch, is currently seeking new funding at a reported $4 billion valuation after an earlier $2 billion Meta acquisition deal fell through.
GoKawiil's interpretation of the reporting above, not reported fact.
The case illustrates a broader risk with agentic AI tools: their usefulness comes from deep integration with a user's other accounts and services, which also multiplies the potential blast radius of a single exploited vulnerability. Because the attack relies on indirect prompt injection—malicious instructions hidden in content the AI later reads, like an email—it could be difficult for users to detect until damage is done. As Manus pursues a higher valuation and wider adoption, unresolved security issues like this could affect investor and enterprise confidence, though the article does not report any confirmed real-world breach.
- Salt Labs disclosed a prompt-injection bug in Manus enabling remote code execution in another user's environment.
- The flaw could extend to any third-party service, like email, connected to a victim's Manus account.
- Manus is seeking funding at a $4 billion valuation after a $2 billion Meta deal was blocked by Chinese authorities.
Source: darkreading.com — Nate Nelson, 2026-09-24
Published there as: “Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.