A SQL injection vulnerability was found in Looker Studio.

A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source.

This vulnerability was patched on 21 July 2025, and no customer action is needed.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no customer action is needed.
Title SQL Injection in Looker Studio
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2025-11-10T15:17:03.069Z

Reserved: 2025-10-28T13:53:53.348Z

Link: CVE-2025-12397

cve-icon Vulnrichment

Updated: 2025-11-10T15:16:58.316Z

cve-icon NVD

Status : Received

Published: 2025-11-10T09:15:41.913

Modified: 2025-11-10T09:15:41.913

Link: CVE-2025-12397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.