Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.7

Azure DevOps AI agent vulnerability allows unauthorized data exfiltration via MCP

A security flaw in Azure DevOps' Model Context Protocol (MCP) implementation allows attackers to bypass permission controls by manipulating AI coding agents. By injecting hidden comments into pull requests, an attacker can trick an AI agent into accessing and leaking data from projects outside the reviewer's authorized scope.

The Hacker News3 days agoUSCredibility 54%View source

Score Breakdown

Mosaic Score7.7
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found