{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "authz_bypass",
  "claimed_impact_class": "authz_bypass",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "requested media path beginning with an allowlisted public prefix followed by dot segments (../) that normalize to a private in-root file; no header/cookie/credential",
  "trigger_path": "GET /media/base/icon/../../<private-in-root> -> base.views.protected_media (1.6.0 b3bd29d1, dev/v2.0 77f515c7)",
  "claimed_surface": "api_remote",
  "validated_surface": "api_remote",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": false,
  "exploit_chain_demonstrated": false,
  "inferred": false
}
