Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
ID: e0c80553-65fa-5ab0-bba6-3f7e8ac8f93e
STIX ID: report--e0c80553-65fa-5ab0-bba6-3f7e8ac8f93e
Feed Name: cybersecurityNews.com
Threat Score
A Manifold Security proof-of-concept shows that hidden HTML comments in Azure DevOps pull request descriptions can perform indirect prompt-injection against AI agents using reviewer credentials, enabling cross-project actions (approve PRs, trigger pipelines, read wikis) and silent data exfiltration; Microsoft had a partial mitigation in place but had not applied it to PR descriptions, no CVE or fix had been released at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
