Breach404
Back to Insights
AI Security2 min readJuly 22, 2026

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A vulnerability in Microsoft Azure DevOps allows attackers to embed hidden commands in pull request comments that can manipulate AI review agents into approving malicious code or executing unintended actions. Organizations using AI-powered code review too

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free