Impact
Magic: The Gathering Arena uses a home‑screen carousel that serves arbitrary URLs to clients. In affected builds, the client forwards a server‑supplied URL from the GoToExternalUrl action straight to the Windows shell via Application.OpenURL/ShellExecuteW. Because the client does not validate the URI scheme or domain, an attacker who controls the carousel content can trigger the execution of any registered URI‑scheme handler without user interaction. This flaw constitutes a local code execution vulnerability (CWE‑99) that could allow execution of arbitrary code or launch of malicious applications on the client machine.
Affected Systems
Vendors: Wizards of the Coast; Product: Magic: The Gathering Arena (Windows/Steam client). Affected releases include build 2026.59.30.12801.127931.6 and certain later 2026.60.x builds. Versions prior to these and other platforms are not known to be affected.
Risk and Exploitability
Attackers would need to inject malicious carousel content onto the servers that deliver the user interface to the game. Once the client receives the crafted URL, it will invoke the specified scheme handler automatically. Because the payload is processed without validation, the attack can succeed without user interaction, but it is limited to local execution on the infected machine. The CVSS score of 3.4 indicates low severity, and the EPSS score is currently unavailable. The vulnerability is not listed in CISA’s KEV catalog, suggesting that it is unlikely to be widely exploited in the near term. Nonetheless, organizations running the game should apply any available patches and consider restricting access to the carousel service and disabling unnecessary URI schemes to reduce the attack surface.
OpenCVE Enrichment