Looker Security Advisory: Cross-Site Scripting Vulnerability
A critical Cross-Site Scripting (XSS) vulnerability in Looker could allow an attacker to execute arbitrary scripts by tricking an administrator into opening a malicious URL. This affects both Looker-hosted and self-hosted instances. Looker-hosted instances are already mitigated, while self-hosted instances require an urgent update to patched versions.
Security (1) ›
- Looker
A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account. Both Looker-hosted and self-hosted instances were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. What should I do? For Looker-hosted instances, no action is required. For self-hosted Looker instances, update your Looker instances as soon as possible. This vulnerability has been
https://docs.cloud.google.com/release-notes#July_22_2026
Related releases
- Google Cloud Conversational Analytics expands across data ecosystem Google Cloud Blog ·
- Open Knowledge Format v0.2 enhances agentic trust and provenance Google Cloud Blog ·
- Looker Reports Deprecated July 2026 Google Cloud release notes ·
- Looker Now Supports Java OpenJDK 21 Google Cloud release notes ·
- Analyze and Govern Gemini Enterprise App Usage with BigQuery Google Cloud Blog ·
- Cloud SDK 576.0.0: BigLake, GKE, Compute Engine updates Google Cloud release notes ·