Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unvalidated URL Execution Enables Arbitrary URI Scheme Invocation |
Thu, 08 Oct 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs. | |
| Weaknesses | CWE-99 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T03:57:54.878Z
Reserved: 2026-10-08T03:57:54.085Z
Link: CVE-2026-107448
No data.
Status : Received
Published: 2026-10-08T04:17:19.640
Modified: 2026-10-08T04:17:19.640
Link: CVE-2026-107448
No data.
OpenCVE Enrichment
Updated: 2026-10-08T05:30:17Z
-
CWE-99
Improper Control of Resource Identifiers ('Resource Injection')