CVE-2025-12155None▾ SunlitA Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted on the host system.…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted on the host system.
Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.
Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ :
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14706Critical· 9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14705Critical· 9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14659High· 8.8A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44