CVE-2025-12742
A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulner…
All CVEs associated with "Looker". Page 1/1 • 13 CVEs.
A curated feed of “Looker”-related CVEs appears below. We currently track 13 CVEs for this tag (all time). In the last 365 days, 11 were published. Average CVSS is 7.4 (all time; 7.5 over 365d), and 85% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE-20 - Improper Input Validation, CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
In our taxonomy this topic maps to a LOW impact class. Analytics and BI systems may expose sensitive datasets. Patch, enforce RBAC and TLS, review sharing policies, and sanitize data exports. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 26.6 | - | Soon | LTS | |
| 26.4 | - | Expired | ||
| 26.2 | - | Expired | ||
| 26.0 | - | Soon | LTS | |
| 25.20 | - | Expired | ||
| 25.18 | - | Expired | LTS | |
| 25.16 | - | Expired | ||
| 25.14 | - | Expired | ||
| 25.12 | - | Expired | LTS | |
| 25.10 | - | Expired | ||
| 25.8 | - | Expired | ||
| 25.6 | - | Expired | LTS | |
| 25.4 | - | Expired | ||
| 25.2 | - | Expired | ||
| 25.0 | - | Expired | LTS | |
| 24.20 | - | Expired | ||
| 24.18 | - | Expired | LTS | |
| 24.16 | - | Expired | ||
| 24.14 | - | Expired | ||
| 24.12 | - | Expired | LTS | |
| 24.10 | - | Expired | ||
| 24.8 | - | Expired | ||
| 24.6 | - | Expired | LTS | |
| 24.4 | - | Expired | ||
| 24.2 | - | Expired | ||
| 24.0 | - | Expired | LTS | |
| 23.20 | - | Expired | ||
| 23.18 | - | Expired | LTS | |
| 23.16 | - | Expired | ||
| 23.14 | - | Expired | ||
| 23.12 | - | Expired | LTS | |
| 23.10 | - | Expired | ||
| 23.8 | - | Expired | ||
| 23.6 | - | Expired | LTS | |
| 23.4 | - | Expired | ||
| 23.2 | - | Expired | ||
| 23.0 | - | Expired | LTS | |
| 22.20 | - | Expired | ||
| 22.18 | - | Expired | LTS | |
| 22.16 | - | Expired | ||
| 22.14 | - | Expired | ||
| 22.12 | - | Expired | LTS | |
| 22.10 | - | Expired | ||
| 22.8 | - | Expired | ||
| 22.6 | - | Expired | LTS | |
| 22.4 | - | Expired | ||
| 22.2 | - | Expired | ||
| 22.0 | - | Expired | LTS | |
| 21.20 | - | Expired | ||
| 21.18 | - | Expired | LTS | |
| 21.16 | - | Expired | ||
| 21.14 | - | Expired | ||
| 21.12 | - | Expired | LTS | |
| 21.10 | - | Expired | ||
| 21.8 | - | Expired | ||
| 21.6 | - | Expired | LTS | |
| 21.4 | - | Expired | ||
| 21.0 | - | Expired | LTS | |
| 7.20 | - | - Expired | ||
| 7.18 | - | - Expired | ||
| 7.16 | - | - Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Looker” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulner…
A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were…
A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of th…
An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker ext…
An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnera…
The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connection name, which is a reserved internal name for Looker's internal MySQL database…
An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command execution on the Looker instance.…
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and exe…
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having…
A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerab…
A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when…
An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker:…
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.