CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2977

As cited

Copy frozen at (site build).

vulnerabilities

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A vulnerability in Microsoft's Azure DevOps MCP server allows an attacker to inject hidden comments into pull requests that can redirect an AI coding agent to unauthorized projects and extract sensitive information. The flaw exists because one tool returns pull request descriptions without adequate prompt-injection protections.

Why it matters: Organizations using Azure DevOps AI agents for code review face unauthorized data exfiltration and lateral movement risks; security teams should review MCP server configurations and apply available mitigations immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A flaw in Microsoft's Azure DevOps Model Context Protocol (MCP) server allows attackers to inject hidden comments into pull requests that manipulate artificial intelligence (AI) coding agents into accessing unauthorized projects and exfiltrating sensitive information. The vulnerability exists because one of the MCP server's tools returns pull request descriptions without prompt-injection protections. An invisible comment can hijack a reviewer's own AI agent to bypass access controls.

Why it matters: Developers and security teams using Azure DevOps with AI coding assistants face risk of unauthorized data access and project compromise through pull request comments; immediate review of AI agent permissions and pull request workflows is warranted.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A flaw in Microsoft's Azure DevOps Model Context Protocol (MCP) server allows attackers to inject hidden comments into pull requests that manipulate artificial intelligence (AI) coding agents into accessing unauthorized projects and exfiltrating sensitive information. The vulnerability exists because one of the MCP server's tools returns pull request descriptions without prompt-injection protections. An invisible comment can hijack a reviewer's own AI agent to bypass access controls.

Why it matters: Developers and security teams using Azure DevOps with AI coding assistants face risk of unauthorized data access and project compromise through pull request comments; immediate review of AI agent permissions and pull request workflows is warranted.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary