{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "serialized hudson.remoting.UserRequest whose Callable bytes are produced by a SpoofedTagSystemClassLoaderOutput (TAG_SYSTEMCLASSLOADER annotation) naming the JEP-200-blocked class hudson.security3911.Payload",
  "trigger_path": "agent -> JNLP4-connect handshake -> hudson.remoting.Channel -> UserRequest.perform -> UserRequest.deserialize -> MultiClassLoaderSerializer$Input.resolveClass -> ClassNotFoundException fallback -> super.resolveClass (unfiltered, pre-fix) -> Payload.readObject executes /bin/sh on controller JVM",
  "claimed_surface": "network_protocol",
  "validated_surface": "network_protocol",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": false,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "bd79015d-a7cd-4f74-bed1-f71f6f9870e8",
    "b2e0df9e-4ba9-4409-ab3b-8832070b1f87"
  ],
  "inferred": false
}
