Hacker News new | ask | show | jobs
by mercxry 2639 days ago
Check if their bug bounty program covers it, if not just report that to them and give them some time, if they don't fix it after that time you can disclose it to the public.