CVE-2026-85520

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE). This issue was fixed in version 2.3.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets2 URLs
Full discourse2 posts
  • mürrez@murrezsec

    🚨 CVE-2026-85520 PoC Released 🔴 Unauthenticated Arbitrary File Write → RCE 📌 PrestaShop Google Merchant Center Feed PoC & technical details: https://pocbit.org/pocs/cve-2026-85520

    0001070
    625 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen PrestaShop gmfeed: Kritische RCE-Lücke in Google-Merchant-Center-Modul geschlossen #cve202685520 #gmfeed #googlemerchantcenterfeed #prestashop https://cybersecurity-news.de/prestashop-gmfeed-cve-2026-85520-rce

    000006
    14 followersView on X

Explore more