The vulnerabilities are described in detail in my blog here: https://conduition.io/code/mercury-disclosure/
reply
Also see the twitter thread here:
reply