A SQL injection vulnerability was found in Looker Studio.
A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source.
This vulnerability was patched on 21 July 2025, and no customer action is needed.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no customer action is needed. | |
| Title | SQL Injection in Looker Studio | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published: 2025-11-10T08:55:05.196Z
Updated: 2025-11-10T15:17:03.069Z
Reserved: 2025-10-28T13:53:53.348Z
Link: CVE-2025-12397
Updated: 2025-11-10T15:16:58.316Z
Status : Received
Published: 2025-11-10T09:15:41.913
Modified: 2025-11-10T09:15:41.913
Link: CVE-2025-12397
No data.