Feeds.4Sysops Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking
Article Content
- •A critical vulnerability in Azure DevOps MCP allows AI agent hijacking via hidden comments.
- •Attackers can exploit this flaw to access sensitive data and trigger unauthorized actions.
- •No patches are currently available, heightening the urgency for organizations to secure their systems.
A critical vulnerability in Microsoft Azure DevOps Model Context Protocol (MCP) server has been identified, allowing attackers to perform indirect prompt injection attacks. By embedding invisible HTML in pull request descriptions, attackers can manipulate AI coding assistants to execute unauthorized actions. This exploitation can lead to accessing confidential wiki pages, triggering pipelines in restricted projects, and exfiltrating sensitive data. The AI agent operates with the reviewer's elevated credentials, amplifying the risk. The vulnerability affects all users of Azure DevOps MCP servers, posing a significant threat to organizations relying on this platform. As of now, no patches have been released to mitigate this vulnerability. Security professionals are advised to monitor for unusual activities related to AI agents and pull requests.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Manifold Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…