Security · 3h ago
Azure DevOps MCP Flaw Lets Hidden Comments Hijack AI Review Agents
A flaw in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden comments in pull requests that hijack AI review agents. The agents can be redirected to unauthorized projects and leak sensitive data. The vulnerability stems from a missing prompt-injection guardrail in a tool that returns PR descriptions.
Meridian48 take
Microsoft's prompt-injection guardrail gap shows how quickly AI agent integrations can become security liabilities when trust boundaries aren't enforced.
Read the full reporting
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents →
The Hacker News
azure-devopsprompt-injection