Looker Security Advisory: Cross-Site Scripting Vulnerability
A critical Cross-Site Scripting (XSS) vulnerability in Looker could allow an attacker to execute arbitrary scripts by tricking an administrator into opening a malicious URL. This affects both Looker-hosted and self-hosted instances. Looker-hosted instances are already mitigated, while self-hosted instances require an urgent update to patched versions.
Security (1) ›
- Looker
A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account. Both Looker-hosted and self-hosted instances were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. What should I do? For Looker-hosted instances, no action is required. For self-hosted Looker instances, update your Looker instances as soon as possible. This vulnerability has been
https://docs.cloud.google.com/release-notes#July_22_2026
Related releases
- Looker Updates: MFA, CI Alerts, UI Enhancements, and AI Features Google Cloud release notes ·
- Cortex Framework v7 GA with modular architecture, Dataform, and AI features Google Cloud release notes ·
- Looker previews verified queries for AI data agent Google Cloud release notes ·
- Looker Agentic Workflows Automate Monitoring and Root Cause Analysis Google Cloud Blog ·
- Google Cloud Conversational Analytics expands across data ecosystem Google Cloud Blog ·
- Open Knowledge Format v0.2 enhances agentic trust and provenance Google Cloud Blog ·