Skip to content
Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking

Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking

First seen 22 Jul 2026, 10:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 23, 2026 at 09:23 UTC
  • A critical vulnerability in Azure DevOps MCP allows AI agent hijacking via hidden comments.
  • Attackers can exploit this flaw to access sensitive data and trigger unauthorized actions.
  • No patches are currently available, heightening the urgency for organizations to secure their systems.

A critical vulnerability in Microsoft Azure DevOps Model Context Protocol (MCP) server has been identified, allowing attackers to perform indirect prompt injection attacks. By embedding invisible HTML in pull request descriptions, attackers can manipulate AI coding assistants to execute unauthorized actions. This exploitation can lead to accessing confidential wiki pages, triggering pipelines in restricted projects, and exfiltrating sensitive data. The AI agent operates with the reviewer's elevated credentials, amplifying the risk. The vulnerability affects all users of Azure DevOps MCP servers, posing a significant threat to organizations relying on this platform. As of now, no patches have been released to mitigate this vulnerability. Security professionals are advised to monitor for unusual activities related to AI agents and pull requests.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 61d ago How this analysis works

Timeline

2026-07-22
Vulnerability disclosed
A critical vulnerability in Azure DevOps MCP server was revealed, enabling indirect prompt injection attacks via hidden HTML.
Feeds.4Sysops
2026-07-22
AI agent exploitation method detailed
The attack method allows unauthorized actions through AI agents using elevated credentials, impacting sensitive data access.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track Manifold Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed