SQL Injection Vulnerability in Looker's Project Generation Feature
CVE-2025-12743
What is CVE-2025-12743?
The vulnerability in Looker's project generation feature allows users to exploit the schemas parameter by using the reserved connection name 'looker'. This scenario facilitates SQL injection, enabling users with developer permissions to execute unauthorized queries against Looker's internal MySQL database. Although Looker-hosted instances have been mitigated automatically, users with self-hosted instances must upgrade to the latest versions for the necessary security improvements. Available patched versions can be found on the Looker download page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Looker-hosted 0 < 24.12.106
Looker Looker-hosted 0 < 24.18.198
Looker Looker-hosted 0 < 25.0.75
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
