You could argue it's beneficial to open source and make it public since it would raise awareness and probably get the root problem fixed rather quickly, as opposed to keeping it to yourself.
Manage the risk. Lots of people knowing = many new threats. keep that stuff a secret or hard to access then only a certain class of threat will present itself. still not great but better.