According to another comment thread here
https://news.ycombinator.com/item?id=15802113 disabling from the GUI re-enabled the bug.
On my laptop I was able to exploit the bug from the local GUI and then disable it from happening (as far as I can tell) by changing the root password from the shell with sudo passwd root and then disabling the root user altogether with dsenableroot -d