A Critical Flaw in Azure DevOps Leaves Developers Open to Hijacked Code Reviews
Microsoft’s Azure DevOps platform has been found vulnerable to a critical flaw, allowing malicious actors to inject hidden comments into code reviews and hijack AI-powered review agents. The vulnerability affects developers worldwide who use the platform for collaborative coding and testing.
The issue lies within the “MCP” (Machine Check Page) feature of Azure DevOps, which enables automated code review using machine learning algorithms. When a developer submits their code for review, the MCP analyzes it to identify potential issues and suggest improvements. However, researchers have discovered that an attacker can inject malicious comments into the code review process, potentially leading to compromised AI-powered agents.
This vulnerability is particularly concerning because it allows attackers to bypass security measures in place to prevent unauthorized access to sensitive information. By manipulating the code review process, a malicious actor could introduce vulnerabilities or steal intellectual property from developers working on high-profile projects. The flaw’s impact extends beyond Azure DevOps users; it also affects other organizations that rely on similar AI-powered review tools.
Microsoft has confirmed the existence of this vulnerability and is working to address it. In the meantime, developers who use Azure DevOps should exercise caution when submitting code for review. This means regularly reviewing the comments and suggestions made by MCP and being vigilant for any suspicious activity. Developers can also take steps to mitigate the risk, such as using secure coding practices and implementing additional security measures to prevent unauthorized access.
The emergence of this vulnerability serves as a reminder that AI-powered tools are not foolproof. While these technologies have revolutionized the way we approach cybersecurity, they are only as secure as the data and processes they rely on. As organizations increasingly adopt AI-driven solutions, it is crucial to acknowledge their limitations and take proactive steps to prevent exploitation.
For developers using Azure DevOps or similar platforms, the takeaway is clear: be cautious of automated code review tools and regularly scrutinize any comments or suggestions made by MCP.
Source: The Hacker News — 2026-07-22