Command Injection Vulnerability in Looker by Google Cloud
CVE-2025-12155
What is CVE-2025-12155?
A security vulnerability in Looker arises from improper file path sanitization, specifically allowing command injection. This issue permits an attacker with Developer permissions to execute arbitrary shell commands when a deletion operation is performed by a user on the host system. While Looker-hosted instances have been patched, users of Self-hosted versions must upgrade to the latest versions to protect against potential exploitation. The vulnerability is now resolved in all supported Self-hosted releases.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Looker-hosted 0 < 24.12.100
Looker Looker-hosted 0 < 24.18.192
Looker Looker-hosted 0 < 25.0.69
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
