This article on a CVE for git published today has details on the vulnerability: https://github.blog/2022-04-12-git-security-vulnerability-an...
The old link also tells you it's a fix for a vulnerability, and also explains how it affects all platforms, and also talks about the use cases etc etc.
The only thing it doesn't have is a CVE number, which I don't think is all that important.
And again, first line says it's a vulnerability. "it does a thing, according to someone posting to HN" is a big fat strawman.
On top of that, it breaks completely valid functionality - someones 'bug' is someone elses feature.
One principle I like to use is to assume readers are smart—e.g. in this case, that readers are smart enough to figure out that there are two relevant links to the comments. Of course randomness is also a factor, but it mostly all works out.