A vulnerability in Azure DevOps MCP allows hidden comments in pull requests to manipulate AI coding agents, granting unauthorized access to source code and secrets. This flaw exposes a critical gap in Microsoft's prompt-injection safeguards, risking information leakage during code review processes.
A security vulnerability has been identified in Microsoft's Azure DevOps MCP. It allows attackers to inject hidden comments into pull requests that can subsequently manipulate AI coding review agents, leveraging the reviewer's credentials to access restricted projects.
The flaw arises from the Azure DevOps pull request system's handling of Markdown content, which accepts HTML comments that remain invisible in the web UI. However, these comments are returned verbatim via the REST API and can be read by AI agents, enabling attackers to silently alter the agents' intended tasks.
The ability for an attacker to utilize the reviewer's access poses significant risks including unauthorized access to source code, secrets, and various work items. Given that reviewers are typically more privileged than the original pull request submitters, this can lead to escalated access for the attacker.
Microsoft has implemented prompt-injection safeguards in other areas of Azure DevOps, but these protections were not applied to the pull request function. Manifold Security noted that similar defense mechanisms should have ideally been employed to secure against this specific vulnerability.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A vulnerability in Azure DevOps MCP allows hidden comments in pull requests to manipulate AI coding agents, granting unauthorized access to source code and secrets. This flaw exposes a critical gap in Microsoft's prompt-injection safeguards, risking information leakage during code review processes.