CVE-2025-12397 Details
Description
A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no customer action is needed.
A SQL injection vulnerability exists in Google Looker Studio reports that use BigQuery as a data source. This issue allows users with report view access to inject malicious SQL that executes with the report owner's permissions. The vulnerability arises from improper sanitization of user input in the batchedDataV2 HTTP request, enabling attackers to manipulate dynamically generated column aliases and execute arbitrary SQL queries. Exploitation could lead to unauthorized data access, modification, or deletion.
Google has patched this vulnerability, and no customer action is needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 10, 2025CISA-ADP
Assessed Nov 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cloud.google.com/support/bulletins#gcp-2025-053 | GoogleCloud | AdvisoryBundleVendor |
| https://www.tenable.com/security/research/tra-2025-28 | GoogleCloud | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | GoogleCloud |
Affected Products
| Product | Versions |
|---|---|
| Google Looker Studio | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | GoogleCloud |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 10, 2025 | New CVE Received | GoogleCloud |
Volerion