Insecure Command Execution in Looker Affects Multiple Versions
CVE-2025-12742
7.5HIGH
What is CVE-2025-12742?
A vulnerability in Looker allows users with a Developer role to potentially execute unauthorized commands due to improper handling of Teradata driver parameters. While Looker-hosted instances have been secured against this issue, users of self-hosted Looker must upgrade to the latest patched versions to mitigate risks. To safeguard your system, it is crucial to download and install the updates provided for affected versions as listed on the Looker download page.
Affected Version(s)
Looker Looker-hosted 0 < 24.12.108
Looker Looker-hosted 0 < 24.18.200
Looker Looker-hosted 0 < 25.0.78
