Description
Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
Published: 2026-10-08
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: Arbitrary code execution via unvalidated URLs
Action: Monitor
AI Analysis

Impact

Magic: The Gathering Arena uses a home‑screen carousel that serves arbitrary URLs to clients. In affected builds, the client forwards a server‑supplied URL from the GoToExternalUrl action straight to the Windows shell via Application.OpenURL/ShellExecuteW. Because the client does not validate the URI scheme or domain, an attacker who controls the carousel content can trigger the execution of any registered URI‑scheme handler without user interaction. This flaw constitutes a local code execution vulnerability (CWE‑99) that could allow execution of arbitrary code or launch of malicious applications on the client machine.

Affected Systems

Vendors: Wizards of the Coast; Product: Magic: The Gathering Arena (Windows/Steam client). Affected releases include build 2026.59.30.12801.127931.6 and certain later 2026.60.x builds. Versions prior to these and other platforms are not known to be affected.

Risk and Exploitability

Attackers would need to inject malicious carousel content onto the servers that deliver the user interface to the game. Once the client receives the crafted URL, it will invoke the specified scheme handler automatically. Because the payload is processed without validation, the attack can succeed without user interaction, but it is limited to local execution on the infected machine. The CVSS score of 3.4 indicates low severity, and the EPSS score is currently unavailable. The vulnerability is not listed in CISA’s KEV catalog, suggesting that it is unlikely to be widely exploited in the near term. Nonetheless, organizations running the game should apply any available patches and consider restricting access to the carousel service and disabling unnecessary URI schemes to reduce the attack surface.

Generated by OpenCVE AI on October 8, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch for Magic: The Gathering Arena once Wizards of the Coast releases it.
  • Restrict network access to the carousel content servers so only authorized servers can supply URLs to the client.
  • Disable or unregister any unnecessary or suspicious URI‑scheme handlers on client Windows machines to limit the potential impact of a ShellExecute.
  • Monitor client activity for unexpected ShellExecuteW calls from the game client.

Generated by OpenCVE AI on October 8, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unvalidated URL Execution Enables Arbitrary URI Scheme Invocation

Thu, 08 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
Weaknesses CWE-99
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T03:57:54.878Z

Reserved: 2026-10-08T03:57:54.085Z

Link: CVE-2026-107448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:19.640

Modified: 2026-10-08T04:17:19.640

Link: CVE-2026-107448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-99

    Improper Control of Resource Identifiers ('Resource Injection')