CVE-2026-85520 is an unauthenticated arbitrary file-write vulnerability in MyPresta Google Merchant Center Feed (gmfeed) for PrestaShop versions 1.9.1 through 2.3.8. The feed.php endpoint permits crafted request parameters to control an output file's name, path, extension, and contents. Missing authentication and input validation permit the malicious write request to be processed, enabling an attacker to place arbitrary PHP code and execute it on the affected PrestaShop server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Python 3 PoC repository for CVE-2026-85520, an alleged unauthenticated arbitrary file-write flaw in MyPresta.eu/VEKIA's Google Merchant Center Feed (gmfeed) module for PrestaShop versions below 2.3.10. The repository contains one executable Python script (poc.py), a detailed README, an example target list, and an MIT license. poc.py uses requests, disables TLS verification, normalizes target URLs, fingerprints gmfeed through feed.php, config.xml, module markers, and static feed files, and parses config.xml version values to identify versions below the stated fixed release. It can perform checks, an optional lightweight aggressive probe, dry-run exploitation, actual marker-file placement and retrieval, concurrent mass processing from a target list, JSONL/text reporting, proxying, and a local mock-lab self-test. The exploitation path targets gmfeed's save-to-file export behavior with attacker-controlled export/file-related parameters and attempts to place a PHP file in the web-accessible module directory. Its default payload is a marker-only PHP execution probe rather than a general interactive shell, but successful execution establishes the practical RCE impact of the arbitrary write primitive.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file-write vulnerability in the Google Merchant Center Feed (gmfeed) module for PrestaShop. Crafted requests to feed.php can control the written file's name, path, extension, and contents, enabling arbitrary PHP code execution and remote code execution.
An unauthenticated arbitrary file-write vulnerability in the MyPresta Google Merchant Center Feed (gmfeed) module for PrestaShop. Attackers can control the written file's path, filename, extension, and contents via feed.php request parameters, enabling arbitrary PHP-code execution and remote code execution.
A critical unauthenticated arbitrary-file-write vulnerability in the Google Merchant Center Feed (gmfeed) module for PrestaShop. Insufficient authentication and input validation in feed.php lets a remote attacker control a written file's path, name, extension, and contents, enabling arbitrary PHP code execution and RCE.
An external control of file name or path vulnerability affecting MyPresta Google Merchant Center Feed software.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.