AI Coding Incident Tracker

Azure DevOps MCP Flaw Hijacks AI Review Agents

Azure DevOps MCP Flaw Hijacks AI Review Agents

Key Questions

What is the Azure DevOps MCP flaw?

Hidden prompt injections in pull request comments can hijack AI review agents through the Azure DevOps MCP server, enabling cross-project access escalation.

How does the vulnerability work?

A single invisible comment in a PR can manipulate an AI coding agent into performing unauthorized actions, exploiting gaps in how agents process untrusted content.

What is the current status of the issue?

A concrete proof-of-concept exists, but the vendor has not responded, highlighting ongoing risks in agent interactions with untrusted inputs.

Hidden PR comments can hijack AI review agents via Azure DevOps MCP server. Cross-project access escalation, vendor non-response. Concrete PoC with spotlighting gap. Fits pattern of agents exploited through untrusted content they read.

Sources (2)
Updated Jul 22, 2026
What is the Azure DevOps MCP flaw? - AI Coding Incident Tracker | NBot | nbot.ai