[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpDlNZROtluYz8q9DYSxWL2pdQ63XP2XpMRaIgg9Q12E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"9af3e912-13f6-4fbe-9a4d-9c142359c02a","hidden-html-comments-in-prs-enable-ai-agent-hijacking-in-azure-devops","1c93c394-8d19-4116-bef8-8ba45fc2b091","Hidden HTML Comments in PRs Enable AI Agent Hijacking in Azure DevOps","This vulnerability exploits a prompt injection attack vector where malicious actors embed hidden HTML comments inside pull requests to manipulate AI coding agents operating with elevated reviewer permissions. Because the AI agent inherits the reviewer's access rights, attackers can pivot laterally to access source code, secrets, and project data they are not authorized to view. This highlights a critical blind spot: AI agents are often granted broad permissions without adequate input validation or output sandboxing, making them attractive targets for privilege escalation. The risk is compounded by the fact that hidden HTML content is invisible to human reviewers but fully parsed by AI models, creating a deceptive attack surface that bypasses traditional code review safeguards.","**Immediate actions:**\n- Audit and restrict AI agent permissions to the minimum required scope, ensuring reviewer-level agents cannot access unrelated projects or repositories.\n- Sanitize and strip hidden HTML comments from pull request content before it is passed as input to any AI review agent.\n- Rotate any secrets or tokens that may have been exposed to AI agents operating in affected Azure DevOps environments.\n\n**Long-term improvements:**\n- Implement a least-privilege model for all AI agent identities, treating them as non-human service accounts subject to strict role-based access control.\n- Establish input validation and prompt sanitization pipelines that detect and block known prompt injection patterns before reaching AI models.\n- Regularly review and scope-limit OAuth tokens and API keys granted to AI integrations to prevent lateral movement upon compromise.\n\n**Detection measures:**\n- Enable detailed logging of all AI agent actions, including repository accesses, API calls, and data reads, and alert on anomalous cross-project activity.\n- Implement behavioral baselines for AI agents so that unexpected data access patterns trigger automated security alerts.\n- Conduct periodic red-team exercises specifically targeting AI-integrated CI\u002FCD pipelines to surface prompt injection and privilege escalation risks.",[12,13,14,15,16,17,18,19,20],"CIS Control 5 – Account Management (Least Privilege)","CIS Control 16 – Application Software Security","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 SI-10 – Information Input Validation","NIST SP 800-53 AU-12 – Audit Record Generation","NIST AI RMF – Govern 1.2, Map 2.3 (AI Risk Management)","OWASP LLM Top 10 – LLM01: Prompt Injection","NIST SP 800-218 (Secure Software Development Framework) – PW.6 (Input Validation)","GDPR Article 32 – Security of Processing (where personal data is accessible via affected repositories)","published","2026-07-22T08:21:42.092891+00:00","2026-07-22T08:21:41.808+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmicrosoft-azure-devops-mcp-flaw-lets.html","microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents-8c8679","Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]