External control of file name or path vulnerability (CVE-2026-85520) has been found in MyPresta Google Merchant Center Feed software.