The Radicle project, which offers a decentralized alternative to platforms like GitHub, revealed in a security disclosure that its network protocol has two critical issues. The first vulnerability undermines confidentiality: the protocol "does not give the confidentiality it was expected to give," meaning anyone who can observe the network traffic between two Radicle nodes can read the data being exchanged. The second flaw breaks peer authentication, enabling an attacker to spoof their Node ID and gain access to private repositories they should not be able to read.
According to the disclosure, the two vulnerabilities are most potent when exploited together. An attacker positioned on the network path between two syncing nodes can see the Node IDs at both ends. Since both IDs are typically on the repository's allow-list, the attacker can read any data exchanged in real time and then, using a captured Node ID, fetch the entire repository on demand. The project warns that "no setting or allow-list protects against them" once an attacker is on the path.
Radicle is publishing the vulnerability report before a security update is available, stating, "You can act on it today, and no fix we release later can undo an exposure that has already happened." The project has outlined workarounds that users can implement immediately, and a major, backward-incompatible update is underway to address the flaws.