#6
The Hacker News
general
July 22, 2026 at 04:57 UTC
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
By [email protected] (The Hacker News)
AI Summary
A prompt injection flaw in Microsoft's official Azure DevOps MCP server allows an attacker to embed invisible instructions in pull request comments, hijacking AI code-review agents to exfiltrate data from repositories the attacker has no access to. The vulnerability exploits a missing prompt-injection guardrail in a tool that returns PR descriptions to the agent. As AI coding agents become standard in DevOps pipelines, this class of attack poses serious supply chain and data exfiltration risks.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →