The Hacker NewsThursday · July 23, 2026FREE

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

azure-devopsmcpai-agentscode-reviewsecurity

A security flaw has been discovered in Microsoft Azure DevOps' implementation of the Model Context Protocol (MCP), which is used to integrate AI agents into code review workflows. The vulnerability allows an attacker to embed hidden comments within pull requests that can hijack AI review agents. These hidden comments can manipulate the AI agent's behavior, potentially causing it to approve or overlook malicious code changes. The attack exploits the way MCP processes comments in pull requests, allowing an attacker to inject instructions that the AI agent follows. This could lead to unauthorized code changes being merged into a codebase without proper human review. The flaw specifically targets organizations that use AI-powered code review agents in Azure DevOps, which are increasingly adopted to automate and accelerate the code review process. The vulnerability highlights a new attack vector where AI agents can be manipulated through their input channels, similar to prompt injection attacks seen in other AI systems. The discovery was reported by security researchers who demonstrated the attack's feasibility. Microsoft has been notified of the issue.

// why it matters

Hidden PR comments can trick AI code reviewers into approving malicious code, bypassing human oversight.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.