Looker Security Advisory: Cross-Site Scripting Vulnerability
A critical Cross-Site Scripting (XSS) vulnerability in Looker could allow an attacker to execute arbitrary scripts by tricking an administrator into opening a malicious URL. This affects both Looker-hosted and self-hosted instances. Looker-hosted instances are already mitigated, while self-hosted instances require an urgent update to patched versions.
Security (1) ›
- Looker
A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account. Both Looker-hosted and self-hosted instances were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. What should I do? For Looker-hosted instances, no action is required. For self-hosted Looker instances, update your Looker instances as soon as possible. This vulnerability has been
https://docs.cloud.google.com/release-notes#July_22_2026
Related releases
- Looker Extension for VS Code Now Generally Available, Adds AI-Assisted LookML Development Google Cloud release notes ·
- Looker Mobile (Legacy) App Deprecation Postponed Google Cloud release notes ·
- Looker 26.16 Rolls Out with Semantic Search GA, Admin Assistant Preview, and Bug Fixes Google Cloud release notes ·
- Google Data Cloud Rolls Out AI-Powered Integrations, Streaming Enhancements, and New Lakehouse Capabilities Google Cloud Blog ·
- Looker Deprecates OpenJDK 11 Support, Requires Upgrade to OpenJDK 21 Google Cloud release notes ·
- Looker enhances EU data processing for Conversational Analytics and deprecates legacy mobile app Google Cloud release notes ·