{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "9afdacf2e6bf4f2c7f2272c33b710fad4510cae47fc281345c171478b151b8da",
    "authored_runtime_manifest_sha256": "60a9fa4bf6eaffa23634a9cb7305f4404ad066466b0fb38f1b706f6b51f3bfdb",
    "authored_verdict_sha256": "0e3de203653e404551e5426b0fda06e83170fdcda593cc1646e92f3d0b194d6e",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "1400df08-d1b7-415f-b8c8-b18b0334c565",
    "37eee6ea-5aa8-41ef-8fd7-2a524d547d55",
    "7b160963-a185-41ce-a8c5-c3a52b1fdd5f",
    "1849abbf-352b-4304-a670-5ffb201bc4d0",
    "ef16459c-4308-4f0c-8107-084ea7c71cd8"
  ],
  "attacker_controlled_input": "Unauthenticated raw HTTP paths containing %5f, simple-action JSON selecting _users, recovered root credential, and authenticated task JSON with isSystem:true plus attacker JavaScript/cron command",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "arangod HTTP listener -> encoded /_db/_system/%5fapi/simple actions -> leaked weak root authData -> /_open/auth -> PUT /_api/tasks/{id} isSystem:true -> Internal JS root crontab write -> crond execution",
  "validated_surface": "api_remote"
}
