CVSS is a ouija board and you can make it say whatever you want, which is why very few practitioners take it seriously.
CVSS scores are put into audit reports --- at the ouiji levels clients want --- to shut up the suits in compliance.
I'm not aware of any programs on HackerOne that don't follow this practice, so it's not "super uncommon".
I modified the assumptions that were made by the reporter and came out with Low.
This is one example of why this is a nonsense metric.