Database Connection Vulnerability in Looker by Google Cloud
CVE-2025-12741
What is CVE-2025-12741?
A vulnerability exists in Looker that allows users with Developer roles to manipulate LookML to execute arbitrary commands via a database connection created with the Denodo driver. Looker-hosted instances have been secured against this issue, requiring no user intervention. However, Self-hosted instances must be upgraded immediately to ensure protection. The vulnerability has been patched in all supported Self-hosted versions—users are encouraged to download the latest updates from the Looker download page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Looker-hosted 0 < 24.12.108
Looker Looker-hosted 0 < 24.18.200
Looker Looker-hosted 0 < 25.0.78
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
