Radicle discloses network-protocol vulnerabilities in all released versions
Radicle says every released version has two critical flaws: node traffic is plaintext, and the peer-authentication handshake permits Node ID impersonation. Private repositories should not be used or seeded over the network until the breaking fix ships; credentials or tokens sent through affected connections should be rotated.
The discussion highlighted that session keys were established but not actually used, that the wire protocol lacks version negotiation, and that the disclosure arrived before a fix because the repair will break compatibility. Commenters also credited Radicle for being unusually candid about the problem.