I think this is a vulnerability in the sense that ability to "View Source" is vulnerability. Some technologies allow users to see the source code. They just work like this. Programmer should be aware of it and should not put any confidential information there.
It's vitally important that anyone building against language models like GPT3 understands prompt injection in depth, so they don't make mistakes like this.