Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Summary

A flaw in Microsoft Azure DevOps allows attackers to use hidden pull request comments to hijack AI coding agents, directing them to unauthorized projects and exfiltrating sensitive data. This vulnerability exploits the server's handling of pull request descriptions, bypassing prompt injection defenses.

IFF Assessment

FOE

This vulnerability allows attackers to compromise AI agents, turning them into tools for data exfiltration and unauthorized access, which is detrimental to defenders.

Severity

8.0 High (AI Estimated)

The vulnerability allows for unauthorized access to sensitive data and code, potentially impacting confidentiality and integrity. The attack vector involves manipulating comments within a trusted platform and leveraging AI agents, indicating a high degree of exploitability and impact.

Defender Context

This incident highlights the emerging risks of AI agents integrated into development workflows, particularly when interacting with code review processes. Defenders should monitor for prompt injection vulnerabilities in AI tools and implement robust input validation for all data processed by AI agents, especially within sensitive environments like Azure DevOps.

Read Full Story →