SQL Injection Vulnerability in Looker's Project Generation Feature
CVE-2025-12743

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 November 2025

What is CVE-2025-12743?

The vulnerability in Looker's project generation feature allows users to exploit the schemas parameter by using the reserved connection name 'looker'. This scenario facilitates SQL injection, enabling users with developer permissions to execute unauthorized queries against Looker's internal MySQL database. Although Looker-hosted instances have been mitigated automatically, users with self-hosted instances must upgrade to the latest versions for the necessary security improvements. Available patched versions can be found on the Looker download page.

Affected Version(s)

Looker Looker-hosted 0 < 24.12.106

Looker Looker-hosted 0 < 24.18.198

Looker Looker-hosted 0 < 25.0.75

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Liv Matan from Tenable
Tomas LaĹľauninkas
.
CVE-2025-12743 : SQL Injection Vulnerability in Looker's Project Generation Feature