Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Summary
A flaw in Microsoft's Azure DevOps MCP server (a tool that lets AI agents read and act on Azure DevOps content) allows attackers to hide malicious instructions in pull request comments using HTML formatting. When a reviewer asks an AI agent to review the PR, the hidden text can trick the agent into accessing projects and data the attacker shouldn't reach, because the agent acts with the reviewer's permissions and the server doesn't filter untrusted content like it does for other tools.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
First tracked: July 22, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%