Threat · curated 30 Jun 2026
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
First reported · updated · 3 reports manifold.security
Coverage timeline
Why it matters
The Azure DevOps MCP flaw shows how attacker-controlled repository content can weaponize a trusted AI review agent to pivot into and leak data from projects across an organization, a growing risk as MCP servers grant agents broad delegated permissions.
Manifold Security disclosed a confused-deputy flaw in Microsoft's official Azure DevOps MCP server where a tool returning pull request descriptions lacked the prompt-injection guardrail applied to other tools, letting a hidden PR comment inject instructions into a reviewer's AI coding agent. The agent then acts with the user's own permissions, reaching projects the attacker cannot access and quietly exfiltrating what it finds; Microsoft addressed it in a fix (v2.8.0).