Tech Radar disclosed that security researchers have successfully bypassed the prompt-injection protections of an AI agent named Manus, achieving code execution through a sophisticated obfuscation technique. This vulnerability highlights the ongoing risks associated with AI agents that are granted broad access to third-party services, even after initial security measures are in place.
Researchers from Salt Labs demonstrated how they could circumvent Manus's security by using JSFuck, an unusual JavaScript obfuscation method. They embedded a hidden prompt within an email, which Manus initially flagged as suspicious. However, by encoding the malicious prompt using JSFuck, the AI agent was tricked into decoding and executing arbitrary JavaScript code within its server-side environment before any security mechanisms could fully intervene. This allowed for a critical security boundary violation, where untrusted email content was transformed into executable code. Although the specific flaw has since been patched by Meta through their bug bounty program, the incident underscores a significant lesson for enterprises deploying AI agents. It emphasizes that while prompt inspection is necessary, it is not sufficient. True security must extend to monitoring and controlling the actions an AI agent takes across all the tools, APIs, and systems it can access, as creative attack methods beyond JSFuck are likely to emerge.
Source: Tech Radar

