Tenable disclosed two vulnerabilities in Google Looker (collectively dubbed “LookOut”) that can enable remote code execution (RCE) and sensitive data exposure, with heightened risk for organizations running customer-hosted/on-premises Looker. Tenable reported an RCE chain involving Git hook overrides that could allow attackers to execute arbitrary commands on the Looker host, potentially leading to full server compromise, theft of secrets, data manipulation, and lateral movement into internal networks; in Google-hosted environments, the technique was described as having potential cross-tenant impact by bypassing isolation controls.
A second issue (tracked as CVE-2025-12743) enables exfiltration of Looker’s internal management database by abusing internal connection behavior, allowing attackers to extract sensitive configuration data and credentials. Google has already remediated the issues in its managed Looker (SaaS) on Google Cloud, but self-hosted deployments remain exposed until patched, with guidance to upgrade to fixed releases (including 25.12.30+, 25.10.54+, 25.6.79+, 25.0.89+, 24.18.209+), and clarification that Looker Studio is not affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage emphasized that successful exploitation could enable server compromise and lateral movement in self-hosted deployments, and potentially cross-tenant access in some Google Cloud Looker environments where shared infrastructure or secrets were reachable. Google also noted exploitation would require a Looker user with developer permissions.
Public reporting included indicators of compromise for self-hosted Looker environments, such as suspicious files in .git/hooks/ and logs showing abuse of internal database connections like looker__ilooker. The guidance was intended to help administrators detect exploitation attempts.
On February 4, 2026, Tenable publicly disclosed technical details for the two Looker flaws, including the RCE chain using LookML remote dependencies, path traversal, Git hook manipulation, and a race condition, as well as CVE-2025-12743 for internal MySQL database exfiltration via request tampering and error-based SQL injection.
Google made patched Looker versions available for customer-hosted and on-premises deployments, with administrators required to manually upgrade. Releases 25.14 and later were reported as unaffected, and the fixes were referenced in Google's bulletin GCP-2025-052.
Google remediated the two Looker issues in its managed Google Cloud-hosted/SaaS offering shortly after Tenable reported them. The fixes addressed the RCE chain and the internal database exposure risk in hosted environments.
Tenable Research identified two vulnerabilities in Google Looker, later dubbed “LookOut,” including an internal database exfiltration flaw and an RCE exploit chain. Google received the report through its vulnerability disclosure process and began remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcetenable.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.