"Unfortunately, large swaths of the security community are fixated on avant garde horrors such as the fact that, during solar eclipses, pacemakers can be remotely controlled with a garage door opener and a Pringles can. It’s definitely unfor- tunate that Pringles cans are the gateway to an obscure set of Sith-like powers that can be used against the 0.002% of the population that has both a pacemaker and bitter enemies in the electronics hobbyist community. However, if someone is motivated enough to kill you by focusing electromagnetic energy through a Pringles can, you probably did something to deserve that. I am not saying that I want you dead, but I am saying that you may have to die so that researchers who study per-photon HMACs for pacemaker transmitters can instead work on making it easier for people to generate good passwords."
I feel like the same thing applies when we are talking about these kind of attacks. I mean right now the latest version of express currently has a dependency on a library that has a known RCE. I mean listen 99% of us work in a company where if someone wanted to steal our information they'd pay the janitor $500 to grab it on his way out. Is this really a huge priority?