AuraLabs Research

Critical Vulnerability in Meta Manus AI Agent Enables Zero-Click Indirect Prompt Injection Attacks

Aurascape Auralabs exposes a security vulnerability, named SilentBridge where everyday workflows can quietly inherit the risk of the tools and data they are allowed to access.

Introduction

Background: SilentBridge and the Risk of Indirect Prompt Injection

Attack Surface in the Manus Agent

SilentBridge-Page: Webpage-Based Indirect Prompt Injection Leading to Gmail Data Exfiltration 

Exploit 2 – Indirect Prompt Injection via Search Results

SilentBridge-Search: Indirect Prompt Injection Delivered via Search Results

SilentBridge-Doc: Prompt Injection Leading to Public Code Server Exposure and Root Command Execution 

Sensitive Data Exposure Inside the Agent Container 

Public Media CDN Without Tenant Isolation 

Sensitive Manus Infrastructure Exposure 

Root Causes: How SilentBridge Emerges 

Recommendations: Designing Against SilentBridge 

The Core Lesson of SilentBridge 

Disclosure Timeline 

Conclusion 

Aurascape Solutions