Threat · curated 30 Jun 2026

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Coverage timeline

discovered manifold.security primary 30 Jun 2026thehackernews.com 22 Jul 2026thehackernews.comesecurityplanet.com

Why it matters

The Azure DevOps MCP flaw shows how attacker-controlled repository content can weaponize a trusted AI review agent to pivot into and leak data from projects across an organization, a growing risk as MCP servers grant agents broad delegated permissions.

Manifold Security disclosed a confused-deputy flaw in Microsoft's official Azure DevOps MCP server where a tool returning pull request descriptions lacked the prompt-injection guardrail applied to other tools, letting a hidden PR comment inject instructions into a reviewer's AI coding agent. The agent then acts with the user's own permissions, reaching projects the attacker cannot access and quietly exfiltrating what it finds; Microsoft addressed it in a fix (v2.8.0).