@silverwizard not really a privsep issue; the component in question is a tiny thing that runs as root for one function that requires it. It was exploitable as a normal user. It was already blocked from merging to prod, dev was just trying to figure out if it worked in a realistic environment and didn't think it through.
Vulns don't respect privsep ?