Description
In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users.
Depending on the sync stream configuration, this could result in authenticated users syncing data that should have been restricted.
Recommendation
Update the @powersync/service-sync-rules package to the latest compatible version. Followings are version details:
- Affected version(s): = 0.32.0
- Patched version(s): 0.33.0
References
Could your website be exposed too?
SmartScanner can check your website for PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3` and gives you actionable findings to investigate.
Start a free scanRelated Issues
- PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3` - @powersync/service-core - CVE-2026-30870
- Angular Expressions - Remote Code Execution using filters - CVE-2026-44643
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163


