Until the situation now, this was limited to the server, not the clients. You could replace the server with Vaultwarden and build it without enterprise features. Not ideal but fine because the server isn't the critical part. It never handles your secrets in any way.
What they tried to do now was integrate proprietary code into the clients that everyone uses. This is a lot more critical as it can access the secrets in plain text.
This also wasn't a "mistake" or "bug", they openly admitted to doing this with the intention of subverting the client code's GPL.
And also in any other filesystem's code or the block layers below the filesystem. As I said, unlikely scenario.