Looker Teradata Driver Parameter Processing Vulnerability in Self-Hosted Instances

Vulnerability

A vulnerability exists in Looker self-hosted instances, allowing users with a Developer role to execute malicious commands. This issue arises from insecure handling of Teradata driver parameters. While Looker-hosted instances have been mitigated, self-hosted users must upgrade to a patched version.

Impact

Exploitation allows for the execution of arbitrary commands within the Looker environment.

Remediation

Self-hosted instances should be upgraded to version 24.12.108+, 24.18.200+, 25.0.78+, 25.6.65+, 25.8.47+, 25.12.10+ or 25.14.

Added: Nov 25, 2025, 6:19 AM
Updated: Nov 25, 2025, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.8
remediation
7.7
relevance
1.2
threat
0.0
urgency
10.0
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.