What happens after a security issue has been reported?
Once the TYPO3 security team receives a notification of an incident, one or more members review it and considers its impact. If TYPO3 or the TYPO3 extension turns out to be actually vulnerable, we work on a fix for the problem. Extension authors are contacted as well, if needed. Finally, the fix is tested, packaged and released. After all of that is done, an advisory is published.
Since all this takes some time, please allow some time for an answer! Please refrain from making anything public before a fix is released - a published vulnerability without a fix is even more severe!