Local Command Execution Vulnerability in Looker by Google
CVE-2025-12740
What is CVE-2025-12740?
In Looker, a flaw exists where users with a Developer role can exploit improperly filtered parameters in the IBM DB2 driver. This allows the execution of unauthorized commands through manipulated LookML scripts. Users of Self-hosted Looker installations are urged to upgrade to the patched versions promptly, while Looker-hosted instances have already received automatic mitigations. Affected Self-hosted versions include those from 25.0.93 upwards to 25.16.44.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Looker-hosted 0 < 25.0.93
Looker Looker-hosted 0 < 25.6.84
Looker Looker-hosted 0 < 25.12.42
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
