{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "crafted .mat (HDF5) file uploaded via POST /rails/active_storage/direct_uploads + PUT to the disk-service token URL, declared as image/png; plus a signed variation token scraped from a public page and, for the RCE stage, an offline-forged variation token minted with the leaked secret_key_base",
  "trigger_path": "GET /rails/active_storage/representations/redirect/:signed_blob_id/:variation_key/:filename -> ActiveStorage::Variant#process -> ImageProcessing::Vips -> Vips::Image.new_from_file -> libvips matload (untrusted) -> matio/HDF5 external storage reads /proc/self/environ; RCE stage: same endpoint with forged {\"instance_eval\": \"<ruby>\"} variation token",
  "claimed_surface": "api_remote",
  "validated_surface": "api_remote",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "f6b3754b-e1b5-41f1-a26b-e3a35a5f3a46"
  ],
  "inferred": false
}
