logo

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

ID: 08f6ccf9-d976-5b99-8cf4-629c40321516

STIX ID: report--08f6ccf9-d976-5b99-8cf4-629c40321516

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: [email protected] (The Hacker News)

...
...

Manifold Security disclosed a confused-deputy prompt-injection flaw in the Azure DevOps MCP server: HTML comments hidden in pull request descriptions are returned raw to AI agents, letting an attacker with PR-write access co-opt a reviewer's agent (which runs with the reviewer’s permissions) to trigger cross-project pipelines and read confidential wiki pages, thereby exfiltrating data. Microsoft implemented a spotlighting guardrail for other response paths but the pull-request path lacked that wrapper; no public fix or CVE was reported as of the write-up and exploitability depends on agent postures that allow tool use without per-action prompts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.