Azure DevOps MCP server lets hidden PR comments hijack AI review agents
Source headline: Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Intelligence Summary
A flaw in Microsoft’s official Azure DevOps MCP server can be triggered via an invisible pull request comment. The tool can return pull request descriptions without the prompt-injection guardrails Microsoft had previously added elsewhere. As a result, a malicious PR comment can manipulate an AI coding review agent to act on content it shouldn’t access. This may cause the agent to reach projects outside the attacker’s permissions and quietly disclose findings. Teams using MCP-based AI review for Azure DevOps should review PR content handling and consider mitigations or upgrades from Microsoft.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.