I wonder what a court would think about who'd be legally liable there?
BigCo or GovDepartment gets popped via a known exploit against a fixed bug in an OSS project, but GitHub has prohibited the project from updating the explicable image they host without paying a ransom of $420/year?
With no way for the person who posted them to ask people not to use them?