Severity: CriticalVulnerabilityPrompt injection
Azure DevOps MCP Server Allows Invisible Comment Prompt Injection Against AI Agents
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
An unsanitized pull request field in Microsoft's official Azure DevOps MCP server enables attackers to inject hidden prompts that hijack an AI agent's execution and bypass authorization boundaries. A malicious actor can use invisible comments to redirect the compromised agent into unauthorized repositories and exfiltrate data it discovers.
What to do
Apply Microsoft's patch to the Azure DevOps MCP server and audit pull request processing for prompt-injection hardening.
Mapped framework pillars
Sources
#MCP#prompt injection#AI agents#Azure DevOps#code review#authorization bypass
