Release is out on Aleph, pip and GitHub.
Update now.
Due to the nature of the issue, I will not disclose any further details for the time being. Once operators have had time to update, I will of course provide a full report for transparency. If you use rnsh, update right now.
Earlier today, I became aware of an issue that has been hiding in rnsh since the very early versions. Most likely, all versions of rnsh are affected. Regrettably, I did not spot this bug when I merged rnsh into RNS as an included utility (at version 1.2.0).
Turnaround time on this issue has been approximately 9 hours. As soon as I became aware of the situation, I dropped everything else to thouroughly analyze it, and implemented a fix, as well as combing over the code for potential similar bugs. It's looking good now, but I can assure that I will take another round at the rnsh code once I've had the chance to catch some sleep.
Important: The new version of rnsh changes default identity file locations, and these will now be sourced from ~/.rnsh/identity (initiator) and ~/.rnsh/identity.default (listener). Make sure you copy your old files to this directory, or specify a custom identity path using the command line arguments. The --config argument has also been renamed to --rnsconfig, and the --config argument will now specify the rnsh configuration directory instead of the RNS configuration directory, bringing the behavior into alignment with other RNS utilities.
See the release changelog for additional details about this release.