AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-12740

UNKNOWN · CVSS N/A EPSS 0.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-24 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2025-12740
Severity
UNKNOWN
CVSS
N/A
EPSS
0.24%

Original NVD Description

A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 25.0.93+ * 25.6.84+ * 25.12.42+ * 25.14.50+ * 25.16.44+