External risk intelligence

PrestaShop Google Merchant Center Feed Arbitrary File Write Leading to RCE

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-85520

The vulnerability resides in a public-facing e-commerce module for PrestaShop. It involves a web endpoint (feed.php) that is designed to be accessed over the internet for feed processing and integration, and the flaw permits unauthenticated interaction, making it inherently exposed to the public internet in normal deployments.

Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in a Google Merchant Center module for PrestaShop allows unauthenticated attackers to write and execute arbitrary code, potentially leading to full system compromise. This issue arises from a lack of authentication and input validation in the feed processing endpoint, enabling attackers to control file names, paths, extensions, and content.

  • Unauthenticated code execution in e-commerce module.
  • Critical flaw risks compromise of merchant data.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to the `feed.php` endpoint. This request manipulates parameters to control the filename, path, extension, and content of a file, ultimately allowing the attacker to write and execute arbitrary PHP code on the server, leading to remote code execution.

  • No authentication required for access.
  • Manipulated request parameters trigger file write.
  • Remote code execution is the likely outcome.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to write arbitrary files to the server by controlling the output file name, path, extension, and content through request parameters. When supported by the advisory, this could lead to the execution of arbitrary PHP code on the affected system.

  • Arbitrary file write to server.
  • Unauthenticated request with crafted parameters.
  • Remote code execution on server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PrestaShop Google Merchant Center Feed module's arbitrary file write vulnerability likely falls under the responsibility of platform or application owners who manage the e-commerce site. The first step is to identify all instances of the affected module, determine their reachability and business criticality, and confirm the accountable owner before planning remediation.

  • Platform or application owners should manage.
  • Verify module reachability and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Google Merchant Center Feed module for PrestaShop?

It is an add-on component for PrestaShop e-commerce stores that bridges product data with Google Merchant Center. Merchants use this module to automatically generate and share catalogs of their inventory, streamlining how products appear in Google search results and shopping advertisements.

How does CWE-73 apply to CVE-2026-85520?

This vulnerability is classified as CWE-73, or External Control of File Name or Path. In this specific case, the module fails to restrict user input for file operations. By sending a malicious request to the feed.php file, an attacker can trick the server into creating or overwriting files in arbitrary locations with custom content, which is the mechanism that enables code execution.

Do I need to be authenticated to trigger this flaw?

No. The flaw exists in an endpoint that does not require any login or administrative credentials to access. If a request is sent to the vulnerable feed.php script with the specific malicious parameters, the application processes it automatically. Standard, legitimate feed requests that do not contain these specific, malformed control parameters do not trigger the vulnerability.

Is my site at risk if it uses this module?

Because the affected feed.php endpoint is designed to be reachable over the internet to function, Halo Surface Signal identifies this as inherently exposed. If your store runs an older version of this module, it is accessible to any remote attacker, making it a high-priority concern for any public-facing merchant site.

When should I update my PrestaShop module?

You should prioritize updating immediately. The first step is to locate all installations of this specific module within your environment to assess whether they are active. Once identified, verify if you are running a version earlier than 2.3.9 and apply the update to patch the input validation errors and secure the feed endpoint.

References