Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Read original article ↗AI Summary
A vulnerability in Microsoft's Azure DevOps MCP server allows attackers to hijack AI review agents via hidden HTML comments in pull request descriptions, enabling unauthorized access to sensitive projects and data. The flaw stems from a missing prompt-injection guardrail, allowing malicious instructions to be executed by AI agents operating with the reviewer's elevated permissions. Although Microsoft acknowledges the issue as a known AI risk, no fix or CVE has been issued yet, and the attack chain remains unpatched. The technique exploits the discrepancy between what humans see and what AI agents process, posing a significant threat in automated review environments.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.