ITSecurityGuru

Malicious Email Could Hijack AI Agent and Access Connected Accounts


Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts.

Researchers at Salt Labs, the research arm of Salt Security, found that Manus could interpret malicious instructions embedded within an incoming email and execute them when asked by a user to check their messages.

Manus is a general-purpose agentic AI platform capable of independently carrying out multi-step tasks including research, data analysis, content creation and software development. The platform can also connect to third-party services such as email, cloud storage and code repositories.

According to Salt Labs, this connectivity created an opportunity for an indirect prompt injection attack, in which malicious instructions contained within external content are interpreted by an AI system as commands.

During testing, researchers initially sent an email containing a direct malicious command. Manus detected and flagged the instruction, suggesting its existing guardrails were capable of recognising the attack.

However, researchers were subsequently able to disguise the command using an obscure JavaScript obfuscation technique. Manus decoded and executed the hidden code and, while the platform produced a security warning, Salt Labs said the warning appeared only after the code had already executed.

The researchers were then able to establish a reverse shell within the environment and locate credentials and tokens associated with third-party services connected to the test account.

According to Salt Labs, a successful real-world exploitation of the vulnerability could therefore have potentially enabled an attacker to reach services including a victim’s email, cloud storage and code repositories.

Significantly, the attack chain did not require the victim to click a malicious link, download a file or hand over their password. Researchers said it required just two events: a malicious email arriving in the victim’s inbox and the user subsequently asking Manus to check their messages.

The vulnerability was responsibly disclosed and has since been resolved, meaning the attack described by Salt Labs is no longer exploitable.

However, the researchers argue the findings demonstrate a wider security challenge facing agentic AI systems: detecting malicious activity may not be enough if an autonomous agent has already performed the action before a human can intervene.

As organisations increasingly give AI agents access to business applications, APIs and sensitive data, Salt Labs said security controls will need to extend beyond inspecting prompts and model behaviour to governing what agents are permitted to do across connected systems.

“The agentic domain is relatively new, and the industry is still learning how to use it correctly, and so are attackers,” said Yaniv Balmas, Head of Research at Salt Security.

“Guardrails are an important part of any agentic system that handles untrusted input, but they are often simply not enough. Anyone designing an agentic system should build robust, layered defenses rather than trusting guardrails to provide all the protection, exactly as we learned to do with traditional services.”

Balmas added that as adoption of agentic AI grows, he expects attacks targeting these systems to become an increasingly common threat vector.



Source link