Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had
This headline and summary belong to the original publisher and are shown here with attribution for our readers; the complete article is available only at the source linked above. Curation and any commentary are by Addroit Nexus and do not imply endorsement by the publisher. Spotted an error or want a story removed? Tell us and we act quickly.