Would you rather have a bug that allows logouts, or a bug that prevents them?
That said, I would love for Facebook to put this snippet in their footer.
Google has an effective way to retaliate. Consider all those non-expert users who type "facebook" in the search bar to get to Facebook and who do not know the difference between the search bar and the location bar.
Google products are pervasively checked for CSRF, in case you were worried that this was a worrying sign. I'm sure they have CSRFs, but not because they don't hunt them down.
You may also get cash+prizes if you submit as you did but don't release it publicly.
Writing CSRF-safe logout would mean that you can't have an href to a static link, and you'd to implement some sort of unique id/key and/or a form post behind the scenes.