Description

PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users syncing data that should have been restricted. Only queries that gate synchronization using subqueries without partitioning the result set are affected. This vulnerability is fixed in 1.20.1.

INFO

Published Date :

2026-03-09T22:31:40.035Z

Last Modified :

2026-03-10T14:14:17.271Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30870 vulnerability.

Vendors Products
Powersync-ja
  • Powersync-service
  • Powersync-service-sync-rules
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-30870.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact