Insecure Command Execution in Looker Affects Multiple Versions
CVE-2025-12742

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
25 November 2025

What is CVE-2025-12742?

A vulnerability in Looker allows users with a Developer role to potentially execute unauthorized commands due to improper handling of Teradata driver parameters. While Looker-hosted instances have been secured against this issue, users of self-hosted Looker must upgrade to the latest patched versions to mitigate risks. To safeguard your system, it is crucial to download and install the updates provided for affected versions as listed on the Looker download page.

Affected Version(s)

Looker Looker-hosted 0 < 24.12.108

Looker Looker-hosted 0 < 24.18.200

Looker Looker-hosted 0 < 25.0.78

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sivanesh Ashok
Sreeram KL
.