{
  "schema_version": 1,
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "Unauthenticated HTTP POST /wp-json/batch/v1 from an isolated Python driver container",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "bypass_target_reached": false,
  "runtime_stack": [
    "stock wordpress:7.0.1-php8.2-apache at sha256:bfc320ed4f02dd3939186b8020de64203a48a939d6dedcf44cb92cf2368923f5",
    "WordPress 7.0.2 source commit 855551c4477bd5a0407221c57dae123c4163b434 over the same pinned PHP/Apache base",
    "mysql:8.0 at sha256:7dcddc01f13bab2f15cde676d44d01f61fc9f99fe7785e86196dfc07d358ae2b with local_infile=0",
    "python:3.12-slim isolated network driver"
  ],
  "source_identities": {
    "vulnerable_commit": "18f793b1f16c1b15b0fc37027f4aeaefab0bfe02",
    "fixed_commit": "855551c4477bd5a0407221c57dae123c4163b434",
    "latest_source_checked_commit": "ace9192af868524bdc49cf4fcb91f4c12c73ee5f"
  },
  "runtime_oracles": {
    "vulnerable_query_scalar_marker_reflected": true,
    "fixed_query_scalar_marker_reflected": false,
    "vulnerable_body_scalar_marker_reflected": false,
    "fixed_body_scalar_marker_reflected": false,
    "fixed_user_count_before_after": "1 -> 1",
    "fixed_post_count_before_after": "4 -> 4",
    "fixed_oembed_count_before_after": "0 -> 0"
  },
  "proof_artifacts": [
    "bundle/logs/vuln_variant/verification_run1.log",
    "bundle/logs/vuln_variant/verification_run2.log",
    "bundle/logs/vuln_variant/two_run_verification.log",
    "bundle/logs/vuln_variant/candidate_matrix.log",
    "bundle/logs/vuln_variant/vulnerable_query_scalar.json",
    "bundle/logs/vuln_variant/fixed_query_scalar.json",
    "bundle/logs/vuln_variant/vulnerable_body_scalar.json",
    "bundle/logs/vuln_variant/fixed_body_scalar.json",
    "bundle/logs/vuln_variant/vulnerable_batch_alignment.json",
    "bundle/logs/vuln_variant/fixed_batch_alignment.json",
    "bundle/logs/vuln_variant/vulnerable_before.log",
    "bundle/logs/vuln_variant/vulnerable_after.log",
    "bundle/logs/vuln_variant/fixed_before.log",
    "bundle/logs/vuln_variant/fixed_after.log",
    "bundle/logs/vuln_variant/source_identity.log",
    "bundle/logs/vuln_variant/static_coverage.log"
  ],
  "notes": "The stage runtime reached and validated the vulnerable primitive and fixed blocking paths. No distinct bypass reached the parent end-to-end administrator/RCE target. Two complete executions returned the expected negative exit code 1."
}
