@powersync/web is vulnerable to Cleartext Transmission of Sensitive Information
30
Low Risk
Affected versions of this package fail to protect against the use of insecure connections when logging in with the token connector. This vulnerability exposes sensitive data to interception, as attackers could potentially exploit.
You are affected if you are using a version that falls within the vulnerable range.
@powersync/web is vulnerable to Cleartext Transmission of Sensitive Information in versions 0.5.1 - 1.10.1.
Upgrade the @powersync/web library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant