Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
ID: 08f6ccf9-d976-5b99-8cf4-629c40321516
STIX ID: report--08f6ccf9-d976-5b99-8cf4-629c40321516
Feed Name: The Hacker News
Manifold Security disclosed a confused-deputy prompt-injection flaw in the Azure DevOps MCP server: HTML comments hidden in pull request descriptions are returned raw to AI agents, letting an attacker with PR-write access co-opt a reviewer's agent (which runs with the reviewer’s permissions) to trigger cross-project pipelines and read confidential wiki pages, thereby exfiltrating data. Microsoft implemented a spotlighting guardrail for other response paths but the pull-request path lacked that wrapper; no public fix or CVE was reported as of the write-up and exploitability depends on agent postures that allow tool use without per-action prompts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
