BlackTree Security · Infrastructure · Automation · AI

Manus Ran Email Code Before Warning the User in Salt’s Test

Salt Labs’ 1 October report covers a Manus flaw public by 24 September. In a controlled test, email content ran code before a warning. Salt says the flaw is resolved, without a fix version or date.

The inbox crossed into an execution path

Salt says disguised email content bypassed a direct-text block and ran through a code-capable tool. Researchers found connected-service tokens in the test sandbox. The report does not establish host escape, root access, a numbered CVE or real-user exploitation.

Review the tool log, not just the final answer. OWASP’s guidance calls for authorisation outside the model. Record what the agent read, the tool it called and whether permission preceded the call.

Put the decision before the action

The NIST concept-paper notice identifies agent identification, authorisation and auditing as design questions. BlackTree’s advice is to map each connected account to the actions an inbox task requires.

Review permissions per workflow, rather than treating “mail connected” as a complete access description.

OWASP recommends narrow functions and downstream permissions, with approval before high-impact actions. A mail summary does not automatically need code execution or sending rights. Enforce those limits at the tool call.

BlackTree’s advice: compare each token’s permitted actions with the mail task. Remove or isolate capabilities the task does not require.

NIST also raises auditing as a design question. BlackTree’s advice is to record the identity, tool request, permission decision and result, so a warning can be distinguished from prevention.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *