CVE-2025-12409: SQL Injection in Looker Studio
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.
This vulnerability was patched on 07 July 2025, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12409?
CVE-2025-12409 is classified as a critical SQL injection vulnerability that can lead to data exfiltration.
How do I fix CVE-2025-12409?
To mitigate CVE-2025-12409, ensure that native functions are disabled in Looker Studio reports.
What impact does CVE-2025-12409 have?
CVE-2025-12409 can allow attackers to execute arbitrary SQL queries, potentially exposing sensitive data from BigQuery.
Who is affected by CVE-2025-12409?
Organizations using Google Looker Studio with enabled native functions for report creation are at risk from CVE-2025-12409.
Is there a workaround for CVE-2025-12409?
Yes, users can restrict access to reports and disable the use of native functions to mitigate the risks posed by CVE-2025-12409.