logo

Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data

ID: e0c80553-65fa-5ab0-bba6-3f7e8ac8f93e

STIX ID: report--e0c80553-65fa-5ab0-bba6-3f7e8ac8f93e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Guru Baran

...
...

A Manifold Security proof-of-concept shows that hidden HTML comments in Azure DevOps pull request descriptions can perform indirect prompt-injection against AI agents using reviewer credentials, enabling cross-project actions (approve PRs, trigger pipelines, read wikis) and silent data exfiltration; Microsoft had a partial mitigation in place but had not applied it to PR descriptions, no CVE or fix had been released at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.