{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "HTTP bodies of POST /app/agents/v1/register (agentDetails XML) and POST /app/agents/v1/commands/error (XStream gadget XML), plus TeamCity-AgentSessionId/TeamCity-AgentCommandId headers",
  "trigger_path": "POST /app/agents/v1/register (unauthenticated session issuance) -> POST /app/agents/v1/commands/error -> Error.fromXml -> unrestricted XStream deserialization -> HSQLMetadataStorage$SchemaMismatchException/BasicDataSource/HashAdapter/TiedMapEntry gadget -> HSQLDB SCRIPT drops .jspws webshell -> GET /<rand>.jspws -> Runtime.exec as tcuser",
  "claimed_surface": "api_remote",
  "validated_surface": "api_remote",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "67dbc81e-5928-4dce-b668-d401c0ae6a54",
    "fa8b1381-141d-4b87-8668-3221b287a7a3"
  ],
  "inferred": false
}
