<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Looker (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/looker.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/looker-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Looker (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-12742 – A Looker user with a Developer role could cause Looker to execute a malicious co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12742</guid>
    <pubDate>Tue, 25 Nov 2025 06:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12742</strong></p>
  <p>A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hosted instances must be upgraded as soon as possible. This vulnerability has been…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12741 – A Looker user with Developer role could create a database connection using Denod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12741</guid>
    <pubDate>Mon, 24 Nov 2025 12:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12741</strong></p>
  <p>A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hosted instances must be upgraded as soon as possible. This vuln…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12740 – A Looker user with a Developer role could create a database connection using IBM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12740</guid>
    <pubDate>Mon, 24 Nov 2025 12:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12740</strong></p>
  <p>A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hoste…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12739 – An attacker with viewer permissions in Looker could craft a malicious URL that, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12739</guid>
    <pubDate>Mon, 24 Nov 2025 10:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12739</strong></p>
  <p>An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12414 – An attacker could take over a Looker account in a Looker instance configured wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12414</guid>
    <pubDate>Thu, 20 Nov 2025 15:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12414</strong></p>
  <p>An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable.  This issue has already been mitigated for Looker-hosted.   Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hoste…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12472 – An attacker with a Looker Developer role could manipulate a LookML project to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12472</guid>
    <pubDate>Wed, 19 Nov 2025 11:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12472</strong></p>
  <p>An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command execution on the Looker instance.    Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hosted instances must be upg…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12405 – An improper privilege management vulnerability was found in Looker Studio. It im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12405</guid>
    <pubDate>Mon, 10 Nov 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12405</strong></p>
  <p>An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors.  A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report.  This vulnerability was patched on 21 July 2025, and no customer action is needed.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12409 – A SQL injection vulnerability was discovered in Looker Studio that allowed for d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12409</guid>
    <pubDate>Mon, 10 Nov 2025 09:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12409</strong></p>
  <p>A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources.   By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.  This vulnerability was patched on 07 July 2025, and no customer action is need…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12397 – A SQL injection vulnerability was found in Looker Studio.

A Looker Studio user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12397</guid>
    <pubDate>Mon, 10 Nov 2025 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12397</strong></p>
  <p>A SQL injection vulnerability was found in Looker Studio.  A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source.  This vulnerability was patched on 21 July 2025, and no customer action is needed.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12155 – A Command Injection vulnerability, resulting from improper file path sanitizatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12155</guid>
    <pubDate>Mon, 10 Nov 2025 09:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12155</strong></p>
  <p>A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted on the host system.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for the…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8912 – An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8912</guid>
    <pubDate>Fri, 11 Oct 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8912</strong></p>
  <p>An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users.  There are two Looker versions that are hosted by Looker:    *  Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated and our investigation has found no signs of exploitation.   *  Looker (original) was not vulnerable to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8912">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
