Microsoft: Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data

Microsoft: Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data

Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding Assistants

Security researchers at Manifold Security uncovered a critical vulnerability in Microsoft’s Azure DevOps MCP server that allows attackers to hijack AI coding assistants and exfiltrate sensitive data from restricted projects. The flaw exploits hidden HTML comments in pull request (PR) descriptions content invisible in the web interface but readable via API to perform indirect prompt injection.

When a victim’s AI agent reviews a malicious PR, it unknowingly executes embedded instructions, such as approving the PR, triggering pipelines in unrelated projects (e.g., "Payments"), and extracting confidential wiki pages. The stolen data is then posted as a PR comment, accessible to the attacker. Since the agent operates under the victim’s credentials, it bypasses access controls, enabling attackers to reach data they couldn’t access directly a classic "confused deputy" attack.

Microsoft had previously implemented "spotlighting" a defense that wraps untrusted content in delimiters to mitigate such risks. However, the fix was applied to pipeline and wiki tools but not PR descriptions, leaving the attack vector open. Manifold Security reported the issue to Microsoft’s Security Response Center, which acknowledged it, though no CVE has been assigned or patch released as of publication.

The incident aligns with Simon Willison’s "lethal trifecta" framework for AI agent risks: access to private data, exposure to untrusted content, and an exfiltration channel. Researchers emphasize that while each agent action appears authorized, the hidden intent and sequence of commands create the threat. The attack highlights the need for continuous monitoring of AI-driven automation, as traditional code audits may miss dynamic, context-aware exploits.

Source: https://cybersecuritynews.com/azure-devops-mcp-flaw/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-azure-devops

"id": "mic1784715975",
"linkid": "microsoft-azure-devops",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Azure DevOps MCP with '
                                              'AI coding assistants',
                        'industry': 'Software/Cloud Services',
                        'name': 'Microsoft',
                        'type': 'Technology Company'}],
 'attack_vector': 'Indirect Prompt Injection via Hidden HTML Comments in PR '
                  'Descriptions',
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'High (restricted projects, '
                                        'confidential information)',
                 'type_of_data_compromised': 'Sensitive project data, '
                                             'confidential wiki pages'},
 'description': 'Security researchers at Manifold Security uncovered a '
                'critical vulnerability in Microsoft’s Azure DevOps MCP server '
                'that allows attackers to hijack AI coding assistants and '
                'exfiltrate sensitive data from restricted projects. The flaw '
                'exploits hidden HTML comments in pull request (PR) '
                'descriptions—content invisible in the web interface but '
                'readable via API—to perform indirect prompt injection. When a '
                'victim’s AI agent reviews a malicious PR, it unknowingly '
                'executes embedded instructions, such as approving the PR, '
                'triggering pipelines in unrelated projects (e.g., '
                "'Payments'), and extracting confidential wiki pages. The "
                'stolen data is then posted as a PR comment, accessible to the '
                'attacker. Since the agent operates under the victim’s '
                'credentials, it bypasses access controls, enabling attackers '
                'to reach data they couldn’t access directly—a classic '
                "'confused deputy' attack.",
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'vulnerability exposure',
            'data_compromised': 'Sensitive data from restricted projects, '
                                'confidential wiki pages',
            'operational_impact': 'Unauthorized data access and exfiltration, '
                                  'potential pipeline triggers in unrelated '
                                  'projects',
            'systems_affected': 'Azure DevOps MCP server, AI coding '
                                'assistants'},
 'investigation_status': 'Acknowledged by Microsoft Security Response Center; '
                         'no CVE assigned or patch released as of publication',
 'lessons_learned': 'The incident highlights the risks of AI-driven '
                    'automation, where traditional code audits may miss '
                    'dynamic, context-aware exploits. Continuous monitoring of '
                    'AI agents is necessary to detect and mitigate such '
                    'threats. The attack also underscores the importance of '
                    'applying security fixes consistently across all '
                    'components (e.g., spotlighting defense for PR '
                    'descriptions).',
 'post_incident_analysis': {'corrective_actions': 'Apply spotlighting defense '
                                                  'to PR descriptions, enhance '
                                                  'monitoring of AI agent '
                                                  'actions',
                            'root_causes': 'Lack of spotlighting defense in PR '
                                           'descriptions, indirect prompt '
                                           'injection via hidden HTML '
                                           'comments, confused deputy attack '
                                           'via AI agent credentials'},
 'recommendations': ['Apply spotlighting defense to PR descriptions in Azure '
                     'DevOps MCP',
                     'Implement continuous monitoring of AI-driven automation',
                     'Audit AI agent actions for hidden or indirect prompt '
                     'injection risks',
                     'Enhance access controls and credential management for AI '
                     'agents'],
 'references': [{'source': 'Manifold Security Research'}],
 'response': {'enhanced_monitoring': 'Recommended for AI-driven automation',
              'third_party_assistance': 'Manifold Security (researchers)'},
 'title': 'Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding '
          'Assistants',
 'type': 'Data Exfiltration',
 'vulnerability_exploited': 'Lack of spotlighting defense in Azure DevOps MCP '
                            'PR descriptions'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.