CVE-2025-12739: Cross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account Compromise
An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance.
Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.
Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : 24.18.201+ 25.0.79+ 25.6.66+ 25.12.7+ 25.16.0+ 25.18.0+ 25.20.0+
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12739?
CVE-2025-12739 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-12739?
To fix CVE-2025-12739, ensure that you update Looker to the latest version that addresses this vulnerability.
What types of Looker instances are affected by CVE-2025-12739?
Both Looker-hosted and Self-hosted instances are affected by CVE-2025-12739.
What is required to exploit CVE-2025-12739?
Exploitation of CVE-2025-12739 requires an attacker to have viewer permissions and at least one Looker extension installed.
Can CVE-2025-12739 lead to unauthorized access?
Yes, CVE-2025-12739 can lead to unauthorized access as it allows for execution of attacker-supplied scripts.