CVE-2026-107448
Received Received - Intake

Arbitrary URI Scheme Execution in Magic: The Gathering Arena

Vulnerability report for CVE-2026-107448, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Wizards of the Coast Magic: The Gathering Arena 2026.59.30.12801.127931.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-99 The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Magic: The Gathering Arena (MTGA) Windows client allows a server-controlled URL to be passed directly to the Windows shell via ShellExecuteW without validating the URI scheme or domain. This means an attacker controlling the carousel content could trick the client into launching arbitrary URI-scheme handlers on the victim's system without user interaction.

Detection Guidance

Check if Magic: The Gathering Arena processes server-supplied URLs without validating URI schemes. Monitor network traffic for unexpected URI scheme handlers being invoked. Test by triggering a benign URI like ms-calculator: to see if it launches automatically.

  • Inspect MTGA client logs for ShellExecuteW calls with non-https/http URIs.
Impact Analysis

An attacker could exploit this to silently launch applications or execute code on your system if a vulnerable URI handler (like ms-msdt for Follina) is registered. For example, a malicious ms-calculator: URI could automatically open Windows Calculator without your consent.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves client-side URI handling in a gaming application rather than data processing or privacy controls. However, if malicious URI handlers were exploited, it could potentially lead to unauthorized system access or data exfiltration, indirectly impacting compliance if sensitive data were involved.

Mitigation Strategies

Disable or uninstall Magic: The Gathering Arena until a patch is available. Block suspicious URI schemes at the firewall or endpoint level. Avoid clicking carousel links in the application.

  • Contact Wizards of the Coast for an official patch or workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107448. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart