Security Flaw Found in Popular AI Agent App 'Manus'
Researchers have identified a prompt-injection vulnerability in Manus, an agentic AI application valued at $4 billion. Prompt injection is a technique where attackers hide malicious instructions inside content that an AI system reads, such as a webpage, document, or email, tricking the AI into taking unintended actions.
The issue highlights a broader risk facing businesses that use AI tools capable of reading and acting on external data. Because these apps often have permissions to browse the web, access files, or send information on a user's behalf, a successful prompt injection could lead to data leakage or unauthorised actions without the user realising anything is wrong.
As AI agents become more common in daily business workflows, security researchers warn that developers need stronger filters to separate trusted instructions from untrusted content the AI encounters.