{
  "attacker_controlled_input": "Unauthenticated /media/<path> URL containing base/icon/../../private-data/... dot-segments; no cookie, authorization header, or Referer is required for the variant.",
  "blocking_mitigation": null,
  "bypass_confirmed": true,
  "claimed_impact_class": "authz_bypass",
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploitability_confidence": "high",
  "fixed_target_tested": {
    "commit_sha": "b3bd29d15819cbece45c58e6268ddd0614e387d6",
    "tag": "1.6.0"
  },
  "inferred": false,
  "notes": "Confirmed bypass: Horilla 1.6.0 returns an unauthenticated private canary when the raw /media/ path starts with public prefix base/icon/ and then uses ../../ to resolve to the private file inside MEDIA_ROOT.",
  "observed_impact_class": "authz_bypass",
  "relation_to_parent": "bypass_of_fixed_release",
  "trigger_path": "/media/base/icon/../../private-data/20260722T061846Z-17685/fixed-secret.txt",
  "validated_surface": "api_remote",
  "variant_outcome": "confirmed",
  "vulnerable_target_tested": {
    "commit_sha": "61bd5173220d19925ad8220db9152a75c881ea73",
    "tag": "1.5.0"
  }
}
