# Hidden PR Comments in Azure DevOps Exploit Allows Hijacking of AI Review Agents

A security flaw in Microsoft Azure DevOps allows attackers to embed hidden comments in pull requests that can hijack AI-powered code review agents. This vulnerability could enable unauthorized code changes or malicious injections into development pipelines. It highlights risks in AI-assisted software workflows.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html) — Wed, 22 Jul 2026 10:27:52 +0530