Full Report
External control of file name or path vulnerability (CVE-2026-85520) has been found in MyPresta Google Merchant Center Feed software.
Analysis Summary
# Vulnerability: Unauthenticated Arbitrary File Write in MyPresta Google Merchant Center Feed
## CVE Details
- **CVE ID**: CVE-2026-85520
- **CVSS Score**: Not explicitly rated in the text, but the impact (Remote Code Execution) typically results in a **Critical** rating (9.0 - 10.0).
- **CWE**: CWE-73 (External control of file name or path)
## Affected Systems
- **Products**: MyPresta Google Merchant Center Feed (gmfeed) module for PrestaShop.
- **Versions**: 1.9.1 through 2.3.8.
- **Configurations**: Systems where the `feed.php` endpoint is accessible.
## Vulnerability Description
The vulnerability arises from a lack of authentication and insufficient input validation in the `feed.php` endpoint. An attacker can manipulate request parameters to control the output file's name, path, extension, and content. Because the application does not verify the user's identity or sanitize the file-related inputs, an attacker can write a malicious file (such as a `.php` script) to a web-accessible directory.
## Exploitation
- **Status**: Reported and fixed; PoC availability is implied by the technical description of the flaw, though not explicitly linked.
- **Complexity**: Low (requires only a crafted HTTP request).
- **Attack Vector**: Network (Remote).
## Impact
- **Confidentiality**: High (Full system compromise via RCE).
- **Integrity**: High (Ability to write/modify files and execute code).
- **Availability**: High (Potential to delete files or crash the service).
## Remediation
### Patches
- **Version 2.3.9**: The vendor has released version 2.3.9 which addresses this vulnerability. Users should update immediately.
### Workarounds
- No specific workarounds were provided; however, restricting access to the `feed.php` file at the server/firewall level or disabling the module until it is patched are standard emergency measures.
## Detection
- **Indicators of Compromise**:
- Presence of unexpected `.php` files in the module's directories or public web folders.
- Unusual POST/GET requests directed at the `feed.php` endpoint containing file paths or PHP code in the parameters.
- **Detection methods and tools**: Monitor web server access logs for anomalous activity involving the `gmfeed` module.
## References
- **Vendor Advisory**: hxxps[://]cert[.]pl/en/posts/2026/09/cve-2026-85520/
- **CVE Record**: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-85520
- **CWE-73 Details**: hxxps[://]cwe[.]mitre[.]org/data/definitions/73[.]html