Any user who knows the accept invitation link format can join groups including private after authorization. It could present a security hole into Vanilla. So before using this functionality with private groups in PROD, need to issue a token/generate invitation code and validate it.