Hard to believe but the moderators of HackerOne didn't think the impact is high enough. I am now sharing the details with ANYONE as this IS a threat...
Would you always think a digest email contains a login link? I don't! And I don't think anyone else should...