A critical vulnerability in Microsoft’s official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which can hijack AI coding agents into performing unauthorized actions. The flaw, detailed by Manifold Security, exploits a missing prompt-injection guardrail in the repo_get_pull_request_by_id tool, enabling a confused-deputy attack where an agent with elevated privileges can be manipulated to access and exfiltrate sensitive data across projects.
The attack works because Azure DevOps PR descriptions support Markdown, including HTML comments that are invisible in the web UI but returned verbatim by the REST API. When a reviewer’s AI agent processes the PR, the hidden text can rewrite the agent’s goals, leveraging the reviewer’s credentials to access source code, secrets, and work items the attacker cannot reach. Manifold’s proof of concept demonstrated exfiltration of a confidential wiki page using Copilot CLI and Claude Code.
Microsoft had already implemented a defense called spotlighting for other tools via PR #1062, but the pull request tool remains unprotected. The company acknowledged the issue as a known class of AI risk but has not released a fix or assigned a CVE as of July 21, 2026. The latest release, v2.8.0, does not address the flaw. Mitigations include least-privilege tokens, scoping agents to specific projects, and monitoring tool traces for suspicious cross-project activity.
Companies: Microsoft, Manifold Security, Invariant Labs
Products: Azure DevOps MCP Server, Copilot CLI, Claude Code
Original source: thehackernews.com