Application security, Third-party code, AI/ML

Researchers bypass AI agent protections with JavaScript obfuscation

Source PC website developer. Real software development code. JavaScript code in text editor. Computer interface. Abstract technology background. Java Software engineer concept.

Tech Radar disclosed that security researchers have successfully bypassed the prompt-injection protections of an AI agent named Manus, achieving code execution through a sophisticated obfuscation technique. This vulnerability highlights the ongoing risks associated with AI agents that are granted broad access to third-party services, even after initial security measures are in place.

Researchers from Salt Labs demonstrated how they could circumvent Manus's security by using JSFuck, an unusual JavaScript obfuscation method. They embedded a hidden prompt within an email, which Manus initially flagged as suspicious. However, by encoding the malicious prompt using JSFuck, the AI agent was tricked into decoding and executing arbitrary JavaScript code within its server-side environment before any security mechanisms could fully intervene. This allowed for a critical security boundary violation, where untrusted email content was transformed into executable code. Although the specific flaw has since been patched by Meta through their bug bounty program, the incident underscores a significant lesson for enterprises deploying AI agents. It emphasizes that while prompt inspection is necessary, it is not sufficient. True security must extend to monitoring and controlling the actions an AI agent takes across all the tools, APIs, and systems it can access, as creative attack methods beyond JSFuck are likely to emerge.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds