๐Ÿ” CVE Alert

CVE-2026-107448

LOW 3.4
CVSS Score
3.4
EPSS Score
0.0%
EPSS Percentile
0th

Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.

CWE CWE-99
Vendor wizards of the coast
Product magic: the gathering arena
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for wizards of the coast magic: the gathering arena

Be the first to know when new low vulnerabilities affecting wizards of the coast magic: the gathering arena are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Wizards of the Coast / Magic: The Gathering Arena
2026.59.30.12801.127931.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/N0tMilk/vulnerability-research/blob/main/Magic/carousel-shellexecute-mtga.md