*Assuming OpenBao has a process in place for this
I'm very disappointed to hear that the researchers didn't do their due diligence and informed the OpenBao project about this issue before publishing
I imagine this is a stressful situation for everyone involved in the project, so I hope the researchers will do some reflections on how they can avoid this situation happening in the future