Radicle's peer-to-peer code forge sends private repositories and metadata in unencrypted cleartext over TCP after its initial Noise handshake, exposing sensitive data to network intermediaries. This vulnerability affects all releases through version 1.10.3 and requires users to tunnel connections through VPNs or other encrypted channels for protection.