{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "JsonMapper variable formula in jsonMapperTest GraphQL mutation: (()=>{const{\"constructor\":F}=Array;return F(<attacker JS>)()})() - quoted PatternProperty key bypasses safeEjs denylist",
  "trigger_path": "POST /graphql jsonMapperTest multipart mutation -> jsonMapper-domain.ts -> parser/json-mapper.ts extractComplexPathFromJson -> safeEjs.ts safeRender -> Function constructor -> child_process.execSync (root); pre-auth via CVE-2026-27960 Bearer admin internal_id",
  "claimed_surface": "api_remote",
  "validated_surface": "api_remote",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "48adcce7-0936-401e-b3b2-f05f9e2fa732",
    "2facf15d-5906-4faa-a130-e6f36b6bba2e"
  ],
  "inferred": false
}
