CERT Polska disclosed CVE-2026-85520, an external control of file name or path vulnerability in MyPresta Google Merchant Center Feed software. The flaw could permit unsafe handling of attacker-influenced file names or paths, creating a potential path-traversal risk.
The available disclosure does not identify affected versions, a CVSS severity score, exploitation in the wild, technical proof-of-concept details, or a vendor-provided remediation. Organizations using the MyPresta module should identify deployed instances, monitor CERT Polska and the vendor for patch guidance, and restrict access to administrative and file-handling functionality pending further details.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-85520 was published for an external-control-of-file-name-or-path flaw (CWE-73) in MyPresta Google Merchant Center Feed. The vulnerable feed.php endpoint lets unauthenticated attackers control the path, name, extension, and contents of written files, potentially enabling remote code execution.
MyPresta fixed CVE-2026-85520 in Google Merchant Center Feed version 2.3.9. The flaw affected versions 1.9.1 through 2.3.8 and allowed unauthenticated arbitrary file writes that could lead to PHP code execution.
Today Group sp. z o.o. responsibly reported the vulnerability in MyPresta’s Google Merchant Center Feed (gmfeed) module for PrestaShop. CERT Polska received the report and coordinated disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcecvefeed.io
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.