A newly disclosed vulnerability in Microsoft’s official Azure DevOps MCP server allows attackers to hide prompt-injection payloads inside HTML comments in pull request descriptions, where they can be consumed by AI coding or review agents but remain invisible to human reviewers. Manifold Security reported that the Azure DevOps API returned PR descriptions verbatim without the existing “spotlighting” safeguards already applied to pipeline and wiki content, creating a confused-deputy condition in which an AI agent can be manipulated into acting with the broader permissions of the user reviewing the PR.
In a proof of concept, the injected instructions led the victim’s AI reviewer to approve a pull request, trigger a pipeline in another project, read a confidential wiki page, and exfiltrate the stolen data by posting it back in a PR comment. Microsoft Security Response Center acknowledged and triaged the report, but no CVE or patch had been released at the time of publication, leaving organizations using AI-assisted Azure DevOps workflows exposed to cross-project data access and unauthorized actions if reviewer permissions are broader than an attacker’s own access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Security Response Center acknowledged and triaged the vulnerability report. At the time of publication, no CVE had been assigned and no patch had been released.
In a proof of concept, the researchers induced an AI coding agent to approve a pull request, trigger a pipeline in another project, read a confidential wiki page, and post the stolen contents back to the attacker through a PR comment.
Manifold Security published details of the Azure DevOps MCP server vulnerability, describing how missing protection on pull request descriptions enabled hidden-comment prompt injection against AI agents.
Manifold Security identified a confused-deputy vulnerability in Microsoft's official Azure DevOps MCP server in which hidden HTML comments in pull request descriptions could indirectly prompt-inject an AI reviewer and abuse the reviewer's broader Azure DevOps permissions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemanifold.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.