Wire Observer.
Technology

Security Flaw Shows Single Email Can Hijack AI Assistant, Researchers Reveal

Security Flaw Shows Single Email Can Hijack AI Assistant, Researchers Reveal

Security researchers have demonstrated that the AI‑driven assistant Manus can be commandeered through a single, specially crafted email, allowing attackers to run arbitrary code on the platform.

Manus, marketed as a versatile agent that integrates with a wide range of third‑party services, relies on prompt‑injection safeguards to block malicious instructions. The researchers found that by embedding a concealed JavaScript payload within the email’s text—obfuscated using the JSFuck technique—they could slip past the system’s filters and trigger execution before the platform flagged the activity as suspicious.

The team’s approach involved hiding the malicious prompt inside what appeared to be a routine message. Once the email was processed, the obfuscated code was decoded by Manus, which then treated the hidden instructions as a legitimate request, resulting in code execution on the host environment. The flaw was discovered after the hidden prompts managed to run unnoticed for a brief window, highlighting a weakness in the assistant’s ability to scrutinize complex, encoded inputs.

Experts say the episode underscores a broader concern: AI agents that enjoy extensive access to external APIs and user data can become high‑value targets if their input validation mechanisms are insufficient. A breach of this nature could enable data exfiltration, unauthorized actions on connected services, or even the deployment of ransomware, depending on the attacker’s objectives.

Following the disclosure, the developers of Manus issued a patch that tightens the inspection of incoming messages and improves detection of JSFuck‑style obfuscation. The incident serves as a cautionary tale for the industry, prompting calls for more rigorous testing of prompt‑injection defenses and greater transparency around the security measures governing AI agents with broad third‑party access.

Source: TechRadar
Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related