An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance.
Looker-hosted and Self-hosted were found to be vulnerable.
This issue has already been mitigated for Looker-hosted instances. No user action is required for these.
Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted.
The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.18.201+
* 25.0.79+
* 25.6.66+
* 25.12.7+
* 25.16.0+
* 25.18.0+
* 25.20.0+
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cloud.google.com/support/bulletins#gcp-2025-068 |
|
History
Tue, 25 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google cloud Looker |
|
| Vendors & Products |
Google
Google cloud Looker |
Mon, 24 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.18.201+ * 25.0.79+ * 25.6.66+ * 25.12.7+ * 25.16.0+ * 25.18.0+ * 25.20.0+ | |
| Title | Cross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account Compromise | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published: 2025-11-24T09:11:38.396Z
Updated: 2025-11-24T13:43:54.837Z
Reserved: 2025-11-05T10:43:57.797Z
Link: CVE-2025-12739
Updated: 2025-11-24T13:24:50.706Z
Status : Awaiting Analysis
Published: 2025-11-24T10:15:59.567
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-12739
No data.