{"id":"CVE-2025-12739","title":"An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script","summary":"An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance.\n\nLoo…","severity":"none","cwe":["CWE-79"],"published":"2025-11-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12739","references":[{"url":"https://cloud.google.com/support/bulletins#gcp-2025-068","label":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"}],"tags":["nvd"],"epss":0.00307,"epssPercentile":0.21534,"ingestedAt":"2026-10-08T10:28:22.136Z","slug":"CVE-2025-12739","body":"## Overview\n\nAn attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance.\n\nLooker-hosted and Self-hosted were found to be vulnerable.\nThis issue has already been mitigated for Looker-hosted instances. No user action is required for these.\n\n\nSelf-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted.\nThe versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page  https://download.looker.com/ :  *  24.18.201+\n  *  25.0.79+\n  *  25.6.66+\n  *  25.12.7+\n  *  25.16.0+\n  *  25.18.0+\n  *  25.20.0+\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}