VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_8c8679da622e5e3cc4400978a2dc773f

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Published Jul 22, 2026

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.

The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.