CVE-2025-12397
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
10/11/2025
Last modified:
12/11/2025
Description
A SQL injection vulnerability was found in Looker Studio.<br />
<br />
A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner&#39;s permissions. The vulnerability affected to reports with BigQuery as the data source.<br />
<br />
This vulnerability was patched on 21 July 2025, and no customer action is needed.



