Description
Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
Published: 2026-10-08
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wizards Of The Coast
Wizards Of The Coast magic The Gathering Arena
Vendors & Products Wizards Of The Coast
Wizards Of The Coast magic The Gathering Arena

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unvalidated URL Execution Enables Arbitrary URI Scheme Invocation

Thu, 08 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
Weaknesses CWE-99
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Wizards Of The Coast Magic The Gathering Arena
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-10T02:56:06.772Z

Reserved: 2026-10-08T03:57:54.085Z

Link: CVE-2026-107448

cve-icon Vulnrichment

Updated: 2026-10-10T02:56:00.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T04:17:19.640

Modified: 2026-10-10T03:17:07.040

Link: CVE-2026-107448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T08:13:51Z

Weaknesses
  • CWE-99

    Improper Control of Resource Identifiers ('Resource Injection')