I'm sad to hear they already know about the vulnerabilities, but glad to hear they acknowledge them and that they should get fixed, plus they got you on the team as well

Naturally it wouldn't be smart to disclose any sensitive details about the application, so I understand completely
