Manus, an agentic AI application valued at $4 billion, has been hit by a prompt-injection bug. The vulnerability allows attackers to embed malicious instructions in external content that the AI agent processes, potentially hijacking its actions.

Prompt injection is a growing concern for AI systems that read web pages, emails, or documents. Because these apps must interpret untrusted data to function, they need exceptionally rigorous security filters to distinguish between legitimate input and hidden commands.

The source notes that most AI apps fall into this category. Without strong safeguards, any application that acts on external data could be turned against its user. The Manus incident is a reminder that agentic AI tools require security review as much as traditional software.