Radicle: Disclosure of Vulnerability in the Network Protocol

Radicle is a peer-to-peer, local-first code collaboration stack built on Git.
Two critical security vulnerabilities in the network protocol used by Radicle nodes were reported.
All versions of Radicle that were released to date are vulnerable.
Network traffic between nodes is not encrypted and not authenticated. Authentication of repository contents via Signed References still detects if attackers along the network path between two nodes modify objects in transit. Thus, the main concern is information leakage, i.e., attackers along the network path between two nodes reading objects in transit. For public repositories, information leakage is less of a concern. However, encryption in transit is crucial for private repositories.
We recommend to stop using private repositories until a fix is released.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in