CVE-2025-12414: Looker account compromise via punycode homograph attack
An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable.
This issue has already been mitigated for Looker-hosted.
Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : 24.12.100+ 24.18.193+ 25.0.69+ 25.6.57+ 25.8.39+ 25.10.22+ 25.12.0+
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12414?
CVE-2025-12414 is categorized as a high severity vulnerability due to its potential for account takeover.
How do I fix CVE-2025-12414?
To fix CVE-2025-12414, ensure that you are using the latest patched version of Looker or implement recommended mitigations for self-hosted instances.
Which versions of Looker are affected by CVE-2025-12414?
CVE-2025-12414 affects Looker versions from 24.12.100 up to 25.12.0, both on Looker-hosted and self-hosted setups.
Is there a workaround for CVE-2025-12414 if I cannot update Looker?
A temporary workaround for CVE-2025-12414 includes disabling OIDC authentication until the situation can be addressed through updates.
Has CVE-2025-12414 been mitigated for Looker-hosted instances?
Yes, CVE-2025-12414 has already been mitigated for Looker-hosted instances.