CVE-2026-107448
Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.
| CWE | CWE-99 |
| Vendor | wizards of the coast |
| Product | magic: the gathering arena |
| Published | Oct 8, 2026 |
Get instant alerts for wizards of the coast magic: the gathering arena
Be the first to know when new low vulnerabilities affecting wizards of the coast magic: the gathering arena are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N