CVE-2026-85520
Last modified
CVE-2026-85520 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters.
Description
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE). This issue was fixed in version 2.3.9.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MyPresta | Google Merchant Center Feed | >= 1.9.1, <= 2.3.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85520?
How severe is CVE-2026-85520?
How do I fix CVE-2026-85520?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85512A security flaw has been discovered in SourceCodester Class …7.3
- CVE-2026-85513A weakness has been identified in StackStorm st2 up to 3.9.0…6.3
- CVE-2026-85514A security vulnerability has been detected in StackStorm st2…6.3
- CVE-2026-85516A vulnerability was detected in code-projects Vehicle Manage…7.3
- CVE-2026-85517A flaw has been found in code-projects Vehicle Management Sy…5.3
- CVE-2026-8552Heap buffer overflow in GPU in Google Chrome on Android prio…4.3
- CVE-2026-85522A vulnerability was detected in valkey-io valkey up to 9.5.4…5.3
- CVE-2026-85525Improper OCSP response validation in the Snowflake Python, G…7.4
- CVE-2026-85526Path traversal in the Btrfs storage driver (unpackVolume) in…9.9
- CVE-2026-85528Improper input validation of the auto-configuration account …5.3
- CVE-2026-8553Use after free in GPU in Google Chrome prior to 148.0.7778.1…3.1
- CVE-2026-85530The GiveWP WordPress plugin before 4.16.8.1 does not consis…8.1
Are you affected by CVE-2026-85520?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
