← Back to feed
AI SecurityEmerging1 sourceAug 25, 2025 · 11:00via Embrace The Red (AI agent security)

How Prompt Injection Exposes Manus' VS Code Server to the Internet

Brief

Today we will cover a powerful, easy to use, autonomous agent called Manus. Manus is developed by the Chinese startup Butterfly Effect , headquartered in Singapore.

This post demonstrates an end-to-end indirect prompt injection attack leading to a compromise of Manus’ dev box.

This is achieved by tricking Manus to expose it’s internal VS Code Server to the Internet, and then sharing the URL and password with the atacker. Specifically, this post demonstrates that:

Read more on Embrace The Red (AI agent security)