The record
Written from the 1 report below. Nothing here is unsourced.
- A vulnerability in Microsoft's official Azure DevOps MCP server lets an attacker hide instructions in HTML comments inside a pull request description, invisible to human reviewers but readable by AI coding agents.
- When a reviewer's agent processes that description, it can be hijacked into using the reviewer's own permissions to access source code, secrets, and work items across projects the attacker cannot reach.
- Security firm Manifold Security found the flaw exists because one tool in the server skips a prompt-injection guardrail Microsoft had already applied to other tools.
- As of July 21 there is no fixed release or CVE, and Microsoft has not said whether it will change the code, calling it a known class of AI risk.
What to watch next
- Whether Microsoft ships a patched release or assigns a CVE for the flaw.
- Whether the hosted remote Azure DevOps MCP server is confirmed exposed, since Manifold only tested the local version.
- Whether the technique moves beyond research into real-world attacks, especially in automated agent workflows.
Coverage1
1 report
English national1
All filed from India
Named United States · Azure DevOps MCP Server · Claude Code · Copilot CLI · GitHub · Invariant Labs · Manifold Security · Microsoft · Simon Willison
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
