CVE-2025-12409: Google Cloud Looker Studio
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery. This vulnerability was patched on 07 July 2025, and no customer action is needed.
Affected products
- Google Cloud Looker Studio: before 2025-07-07 (fixed in 2025-07-07)
Published 2025-11-10. Last modified 2026-10-07.