CVE-2026-30870 Details
Description
PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users syncing data that should have been restricted. Only queries that gate synchronization using subqueries without partitioning the result set are affected. This vulnerability is fixed in 1.20.1.
A vulnerability in PowerSync Service version 1.20.0 allows authenticated users to sync restricted data when using new sync streams with config.edition: 3. Certain subquery filters were ignored, leading to unauthorized data synchronization. This issue affects queries that use subqueries to control synchronization without partitioning the data, while those that do partition data are not impacted.
Users can update to PowerSync Service version 1.20.1 to address this vulnerability. For self-hosted PowerSync instances, updating to the latest version and restarting the service is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 10, 2026CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/powersync-ja/powersync-service/security/advisories/GHSA-q6wc-xx4m-92fj | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| @powersync/service-core | All versions |
CPE
Remediation
| |
| @powersync/service-sync-rules | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | New CVE Received | [email protected] |
Volerion