AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-12409

UNKNOWN · CVSS N/A EPSS 0.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-10 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It involves a SQL injection risk.

CVE
CVE-2025-12409
Severity
UNKNOWN
CVSS
N/A
EPSS
0.24%

Original NVD Description

A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery. This vulnerability was patched on 07 July 2025, and no customer action is needed.