Disclosure of Vulnerability in the Network Protocol

Radicle is a peer-to-peer, local-first code collaboration stack built on Git.

Summary

What happened?

Two critical security vulnerabilities in the network protocol used by Radicle nodes were reported.

Which versions are affected?

All versions of Radicle that were released to date are vulnerable.

What is the issue?

Network traffic between nodes is not encrypted and not authenticated. Authentication of repository contents via Signed References still detects if attackers along the network path between two nodes modify objects in transit. Thus, the main concern is information leakage, i.e., attackers along the network path between two nodes reading objects in transit. For public repositories, information leakage is less of a concern. However, encryption in transit is crucial for private repositories.