Back to all news
Security

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

The Hacker News·July 22, 2026·1 min read
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A flaw in Microsoft's official Azure DevOps MCP server allows a single invisible comment in a pull request to turn an AI coding agent against its user. The vulnerability enables attackers to access projects they lack rights to and leak findings. The issue stems from a tool returning descriptions without a prompt-injection guardrail Microsoft had implemented.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store