Microsoft Azure DevOps MCP Server Vulnerability Allows Hidden PR Comments to Manipulate AI Review Agents
A vulnerability in Microsoft Azure DevOps MCP server allows hidden PR comments to manipulate AI review agents into accessing unauthorized projects and leaking data. The flaw exploits a missing prompt-injection guardrail in pull request descriptions, enabling attackers to leverage reviewer credentials for cross-project actions.
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.
The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had
*** END OF TRANSMISSION ***