PT-2026-24089 · @Powersync · Powersync

Moderaterkistner

·

Published

2026-03-07

·

Updated

2026-03-10

·

CVE-2026-30870

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PowerSync versions prior to 1.20.1
Description The PowerSync Service, a server-side component of the PowerSync sync engine, had an issue in version 1.20.0 where subquery filters were ignored when determining data synchronization for users with new sync streams and config.edition: 3. This could allow authenticated users to access data they should not have been able to sync. Only queries that use subqueries without partitioning the result set were affected. The issue did not impact sync rules, sync streams using config.edition: 2, or scenarios where authentication was not used. Affected queries included those that determine table synchronization based on subqueries, such as selecting data only for admin users or authorized users. Examples of vulnerable queries include those using auth.user id() and auth.parameter() within subqueries to filter data.
Recommendations Update PowerSync to version 1.20.1 or later. Restart the service after updating.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-30870
GHSA-Q6WC-XX4M-92FJ

Affected Products

Powersync