Latest Hacking News
Read post

Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It

Researchers at Manifold Security disclosed a vulnerability in Microsoft's Azure DevOps MCP server where HTML comments hidden in pull request descriptions can be used to hijack AI coding agents via prompt injection. The flaw exists because the PR retrieval tool, unlike wiki and build log tools, does not wrap untrusted content in delimiters, so hidden instructions reach the model as trusted text. An attacker with write access to one repo can exploit a victim's agent to traverse the entire organization using the victim's permissions. Practical mitigations include scoping PATs to single projects, restricting MCP tool domains to only what the task requires, requiring human approval for cross-project actions, and logging agent activity. No CVE or patch exists yet. The broader lesson applies to any MCP server that feeds agent-readable content authored by untrusted parties.

    #security#ai-agents#mcp#prompt-injection#azure-devops
Jul 26•5m read time•From latesthackingnews.com
Post cover image
Table of contents
What makes the Azure DevOps MCP flaw exploitableCheck whether your setup is exposedWhat to change nowWhy the usual advice falls short here
130 Impressions
Latest Hacking News's image
Latest Hacking News

LHN is a renowned programming languages weblog, offering insights into the theory, design, and imple...

252 Followers

•

342 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard