PT-2026-24089 · @Powersync · Powersync
Moderaterkistner
·
Published
2026-03-07
·
Updated
2026-03-10
·
CVE-2026-30870
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PowerSync versions prior to 1.20.1
Description
The PowerSync Service, a server-side component of the PowerSync sync engine, had an issue in version 1.20.0 where subquery filters were ignored when determining data synchronization for users with new sync streams and
config.edition: 3. This could allow authenticated users to access data they should not have been able to sync. Only queries that use subqueries without partitioning the result set were affected. The issue did not impact sync rules, sync streams using config.edition: 2, or scenarios where authentication was not used. Affected queries included those that determine table synchronization based on subqueries, such as selecting data only for admin users or authorized users. Examples of vulnerable queries include those using auth.user id() and auth.parameter() within subqueries to filter data.Recommendations
Update PowerSync to version 1.20.1 or later. Restart the service after updating.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powersync