{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "Malicious JSON Schema customBasePath extension value containing a newline plus a dot-free Python expression (print(...) writing a marker file), supplied to the datamodel-codegen CLI.",
  "trigger_path": "datamodel-codegen CLI --input malicious_schema.json --input-file-type jsonschema --output <generated.py>; importing the generated module executes the injected print() at module top level.",
  "claimed_surface": "cli_local",
  "validated_surface": "cli_local",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "c58b8b34-7755-40db-91dc-6be152b117d6",
    "c6f7f0c4-5aa1-47c0-b529-29275f1b23f1"
  ],
  "inferred": false
}
