Impact
A Cross‑Site Scripting (XSS) flaw allows malicious code to be injected into a URL that an administrator will open, executing the JavaScript with administrative privileges. The attack can result in full takeover of the Looker instance, enabling an attacker to modify settings, access sensitive data, or disrupt operations. The weakness is identified as CWE‑79, a classic reflected XSS vulnerability.
Affected Systems
Both Google Cloud Looker hosted services and self‑hosted installations are affected if they run any of the versions below the listed patches: 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, or 26.8.7. Google has already mitigated the issue for Looker‑hosted instances, so no action is needed for customers on that platform. Self‑hosted customers must upgrade to one of the patched releases or newer.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity flaw, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, meaning no public exploitation has been reported. Attackers can exploit the flaw by crafting a malicious link and convincing an administrator to visit it. User training and strict URL sanitization are critical mitigating controls. Implementing a robust Content Security Policy will also limit successful exploitation.
OpenCVE Enrichment