CVE-2026-85520
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Summary
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE).
This issue was fixed in version 2.3.9.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MyPresta | Google Merchant Center Feed | 1.9.1 <= 2.3.8 | affected |
Weaknesses
- CWE-73: CWE-73 External control of file name or path
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://cert.pl/en/posts/2026/09/CVE-2026-85520
- https://mypresta.eu/news/google-merchant-center-security-fix-2026.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.