Skip to content
Agentic AI Security Hub
Back to feed
Severity: CriticalVulnerabilityPrompt injection

Azure DevOps MCP Server Allows Invisible Comment Prompt Injection Against AI Agents

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

An unsanitized pull request field in Microsoft's official Azure DevOps MCP server enables attackers to inject hidden prompts that hijack an AI agent's execution and bypass authorization boundaries. A malicious actor can use invisible comments to redirect the compromised agent into unauthorized repositories and exfiltrate data it discovers.

What to do

Apply Microsoft's patch to the Azure DevOps MCP server and audit pull request processing for prompt-injection hardening.

#MCP#prompt injection#AI agents#Azure DevOps#code review#authorization bypass