Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Read full story on The Hacker News
Share
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
AI disclosure

Summary

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had

Discussion on

Trending posts from X.

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.