Skip to content
Prompt-Injection Vulnerability Exposes Manus AI to Remote Code Execution

Prompt-Injection Vulnerability Exposes Manus AI to Remote Code Execution

First seen 26 Sep 2026, 04:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 26, 2026 at 05:24 UTC
  • •Manus AI has a critical prompt-injection vulnerability allowing remote code execution.
  • •The flaw can be exploited via indirect prompt injections, impacting connected third-party services.
  • •Security researchers successfully bypassed Manus's security measures using JavaScript obfuscation.

A prompt-injection vulnerability in Manus, a rapidly growing agentic AI app, has been identified by Salt Labs, allowing remote code execution (RCE) in user environments. Manus, valued at $4 billion, faced a blocked acquisition by Meta due to Chinese regulatory actions. The vulnerability permits attackers to exploit indirect prompt injections, potentially leading to data theft and unauthorized actions in connected third-party applications. Although Manus has security measures to block plaintext execution requests in emails, researchers managed to bypass these protections using JSFuck obfuscation techniques. The flaw poses significant risks, especially for users integrating Manus with sensitive services like email. The situation is under active scrutiny as researchers continue to explore the implications of this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2025-03-01
Manus AI launched
Manus AI app launched and quickly gained 2 million users on its waitlist.
Darkreading
2026-04-01
Meta's acquisition blocked
Chinese regulators formally blocked Meta's planned $2 billion acquisition of Manus AI.
Oodaloop
2026-09-24
Vulnerability disclosed
Salt Labs disclosed a prompt-injection vulnerability in Manus, allowing RCE.
Darkreading
2026-09-25
Research findings published
Oodaloop reported on the indirect prompt-injection flaw and its implications for Manus users.
Oodaloop

More articles in this cluster (2)

Following this threat?

Track Manus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed