Critical security vulnerabilities in the Radicle network protocol
Radicle, the peer-to-peer code-collaboration project, has disclosed two critical vulnerabilities in its network protocol. The first breaks confidentiality, letting anyone observing traffic between two nodes read exchanged data. The second breaks peer authentication, allowing Node ID spoofing so an attacker can impersonate a trusted peer and read private repositories. Combined, an on-path attacker can eavesdrop and then fetch entire repositories on demand, and no allow-list setting protects against this. The disclosure was published ahead of an available fix, urging users to apply workarounds now, while a backward-incompatible major update is underway.
