---
id: CVE-2025-12409
title: >-
  A SQL injection vulnerability was discovered in Looker Studio that allowed for
  data exfiltration from BigQuery data sources.
   
  By creating a malicious report with native functions enabled, and having the
  victim access the report, an atta…
summary: >-
  A SQL injection vulnerability was discovered in Looker Studio that allowed for
  data exfiltration from BigQuery data sources.
   
  By creating a malicious report with native functions enabled, and having the
  victim access the report, an atta…
severity: none
cwe:
  - CWE-89
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12409'
references:
  - url: 'https://cloud.google.com/support/bulletins#gcp-2025-053'
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
  - url: 'https://www.tenable.com/security/research/tra-2025-27'
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
epss: 0.00251
epssPercentile: 0.15098
ingestedAt: '2026-10-07T21:54:15.001Z'
---

## Overview

A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources.
 
By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.

This vulnerability was patched on 07 July 2025, and no customer action is needed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
