If it can be patched server side there's literally no reason to hold it, seems like you're just trying to imitate other exploits which get held privately. The reason people don't publish entry points and vulnerabilities right away is so that they don't get patched in future system updates (or...