Security researchers at Salt Labs disclosed a prompt-injection vulnerability in Manus, an agentic AI app valued near $4 billion, that allowed remote code execution in a victim’s Manus environment. The researchers hid instructions inside an email that Manus later read, using an obfuscated JavaScript technique (JSFuck) to bypass the platform’s guardrails before its security filter could catch the attack. The flaw exposed credentials for any third-party app a victim had connected to Manus, such as Gmail, Dropbox, or GitHub. Manus’s developer did not respond to the report, but the flaw was triaged, confirmed, and patched through Meta’s bug-bounty program.