{
  "claim_outcome": "confirmed",
  "claim_block_reason": null,
  "repro_result": "confirmed",
  "validated_surface": "cli_local",
  "evidence_scope": "production_path",
  "claimed_impact_class": "sandbox_escape",
  "observed_impact_class": "sandbox_escape",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "filesystem content bound into the sandbox (untrusted tree containing symlink subdir -> /oldroot<host_target>), plus marker file content via --file fd",
  "trigger_path": "bwrap --bind <untrusted> / --dir /subdir/newdir --file 3 /subdir/newdir/ESCAPE_MARKER.txt /usr/bin/true; setup_newroot() -> mkdir_with_parents('/newroot/subdir/newdir') follows the absolute symlink into /oldroot (host)",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "blocking_mitigation": null,
  "inferred": false
}
