Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking

Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking

First seen 22 Jul 2026, 10:22 UTC ThehackernewsFeeds.4Sysops 77% similarity 66.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Microsoft Azure DevOps Model Context Protocol (MCP) server has been identified, allowing attackers to perform indirect prompt injection attacks. By embedding invisible HTML in pull request descriptions, attackers can manipulate AI coding assistants to execute unauthorized actions. This exploitation can lead to accessing confidential wiki pages, triggering pipelines in restricted projects, and exfiltrating sensitive data. The AI agent operates with the reviewer's elevated credentials, amplifying the risk. The vulnerability affects all users of Azure DevOps MCP servers, posing a significant threat to organizations relying on this platform. As of now, no patches have been released to mitigate this vulnerability. Security professionals are advised to monitor for unusual activities related to AI agents and pull requests.

Key Points: • A critical vulnerability in Azure DevOps MCP allows AI agent hijacking via hidden comments. • Attackers can exploit this flaw to access sensitive data and trigger unauthorized actions. • No patches are currently available, heightening the urgency for organizations to secure their systems.

ThreatCluster AI

Timeline

2026-07-22
Vulnerability disclosed
A critical vulnerability in Azure DevOps MCP server was revealed, enabling indirect prompt injection attacks via hidden HTML.
Feeds.4Sysops
2026-07-22
AI agent exploitation method detailed
The attack method allows unauthorized actions through AI agents using elevated credentials, impacting sensitive data access.
Thehackernews

Community

Browse all →