{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "Unauthenticated POST /api/og; raw request body enters SVG <title> rendered by Node.js next/og ImageResponse",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "official Node.js v24.20.0 linux-x64",
    "Next.js 16.3.5 next start (vulnerable) / 16.3.6 (fixed)",
    "next/og ImageResponse",
    "sharp 0.35.4",
    "libvips 8.18.6",
    "librsvg 2.62.91",
    "libxml2 2.15.3"
  ],
  "target_identity": {
    "repository_url": "https://github.com/vercel/next.js",
    "target_digest": "40eb48bc9707b3d23dcdabd8d4ab837ce40de70df8636e7b0560226b1a74a234",
    "runtime_digest": "89af8424dd53e560b1933f87ba650d8bf57c83ca5a04600eefb31f416aabbae7",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "repro/proof/runtime_identity.json",
    "repro/proof/evaluation.json",
    "repro/proof/vulnerable_attempt1/request.json",
    "repro/proof/vulnerable_attempt1/request.body",
    "repro/proof/vulnerable_attempt1/payload_generation.log",
    "repro/proof/vulnerable_attempt1/response.headers",
    "repro/proof/vulnerable_attempt1/http_status.txt",
    "repro/proof/vulnerable_attempt1/server.log",
    "repro/proof/vulnerable_attempt1/observation.json",
    "repro/proof/vulnerable_attempt1/marker.txt",
    "repro/proof/vulnerable_attempt2/request.json",
    "repro/proof/vulnerable_attempt2/request.body",
    "repro/proof/vulnerable_attempt2/payload_generation.log",
    "repro/proof/vulnerable_attempt2/response.headers",
    "repro/proof/vulnerable_attempt2/http_status.txt",
    "repro/proof/vulnerable_attempt2/server.log",
    "repro/proof/vulnerable_attempt2/observation.json",
    "repro/proof/vulnerable_attempt2/marker.txt",
    "repro/proof/fixed_attempt1/request.json",
    "repro/proof/fixed_attempt1/request.body",
    "repro/proof/fixed_attempt1/payload_generation.log",
    "repro/proof/fixed_attempt1/response.headers",
    "repro/proof/fixed_attempt1/http_status.txt",
    "repro/proof/fixed_attempt1/server.log",
    "repro/proof/fixed_attempt1/observation.json",
    "repro/proof/fixed_attempt1/response.body",
    "repro/proof/fixed_attempt2/request.json",
    "repro/proof/fixed_attempt2/request.body",
    "repro/proof/fixed_attempt2/payload_generation.log",
    "repro/proof/fixed_attempt2/response.headers",
    "repro/proof/fixed_attempt2/http_status.txt",
    "repro/proof/fixed_attempt2/server.log",
    "repro/proof/fixed_attempt2/observation.json",
    "repro/proof/fixed_attempt2/response.body"
  ],
  "artifact_sha256": {
    "repro/proof/runtime_identity.json": "fa91aca374058be48cee25ba553613c2f9d200010d4a8ac9ede7197d1321e761",
    "repro/proof/evaluation.json": "56e8c02ed8c71080f59af48a838725bba4303c56b3f1cf339de140e6209340c0",
    "repro/proof/vulnerable_attempt1/request.json": "1156e80afc77cf85832dc1892807d78025fb1e780763bfef222684c5d9b5052e",
    "repro/proof/vulnerable_attempt1/request.body": "a28c8c75b920f28233faa8c743a1b9047a1096f59d5678f8cd902ddfe86e50cc",
    "repro/proof/vulnerable_attempt1/payload_generation.log": "e52a876042fc385be665cb78eb14d9fb7b56bcdf399c8972edb2b4aa7c8e3db3",
    "repro/proof/vulnerable_attempt1/response.headers": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "repro/proof/vulnerable_attempt1/http_status.txt": "945e4893567554e68f6f28d5652917269341a5f3d295a16b7c708c9bfd95dc5d",
    "repro/proof/vulnerable_attempt1/server.log": "5f8cb81d21d2121e738eb274933385db0fdee20c7e3f873ab13661c4fca2255b",
    "repro/proof/vulnerable_attempt1/observation.json": "35ef6193cc085fd2bc188aff7049b6fae81f136a5e3c56257e55f5a2e8f09ed9",
    "repro/proof/vulnerable_attempt1/marker.txt": "9edf37e593bd4d4eabcdc7e1173702b2d0ab1307adab36265afd9bb487c0bffa",
    "repro/proof/vulnerable_attempt2/request.json": "d59237ba41dbb1be08a29a5320bd550d60d08eebffbe2ea20067c72f07776121",
    "repro/proof/vulnerable_attempt2/request.body": "68e42e73b1f4135fb980aefcbbcd0efc175e605ce9c6460392efc48c8b66b720",
    "repro/proof/vulnerable_attempt2/payload_generation.log": "62dcc402efbc883366f2b50cf298114bc08b4651ecb0cc83ee12d1a197f08d23",
    "repro/proof/vulnerable_attempt2/response.headers": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "repro/proof/vulnerable_attempt2/http_status.txt": "945e4893567554e68f6f28d5652917269341a5f3d295a16b7c708c9bfd95dc5d",
    "repro/proof/vulnerable_attempt2/server.log": "c95818fa91029ef53f6aedd188bb8679dc7a9d09e88a2644155bc5d50f4283de",
    "repro/proof/vulnerable_attempt2/observation.json": "fbb1d1ec6e949f4ae819ce374a4dd80a79e3a4133e89bf52fc7e00b210dd4761",
    "repro/proof/vulnerable_attempt2/marker.txt": "f35499c917d8786cb30e69cfa0d2aa9dc0b9f58273e657ca5d1650b9edd33220",
    "repro/proof/fixed_attempt1/request.json": "9e12f038afa4151e534dbf5f2c6d3b3fda52152d1f1a41844a80b0b7e7673ec6",
    "repro/proof/fixed_attempt1/request.body": "2d2a572e5e3cd96ad53067054ef440079303a0634acaccb1f2e85c141325f258",
    "repro/proof/fixed_attempt1/payload_generation.log": "09ff78264182be711bcb16544363de2e7ae3a1f0e7ed47092e59c5b69e27a330",
    "repro/proof/fixed_attempt1/response.headers": "7c18364c4366fece50f8a3d5b3153bfe80390f51b428e246ec51816f2f236e16",
    "repro/proof/fixed_attempt1/http_status.txt": "c11e3f4837efde2441e23a7b9da02131f53bf59fddeb7147c4ab81afe400460f",
    "repro/proof/fixed_attempt1/server.log": "e617600b3f063bbce29a42eb2afb48af37281307d9e0bd55cfa763a376b242ef",
    "repro/proof/fixed_attempt1/observation.json": "b72e058f553ef2804de104bd9cb9607805b4237dfd8b19b874f640d87b4558a1",
    "repro/proof/fixed_attempt1/response.body": "d32aaaa18a48081a0b52df0bc72397d90f78035ea5d7b095be8ba8bb315c51ce",
    "repro/proof/fixed_attempt2/request.json": "ff156870a3f3767cbacfb3d4182fc8c56537ed148e40584fb6abd7bd9b24f184",
    "repro/proof/fixed_attempt2/request.body": "cfc314d3e4e38c953910ae00640141eb9a196c73c572f06ef5bc67f42989535e",
    "repro/proof/fixed_attempt2/payload_generation.log": "3abc408774d90395f97ad6f9df5294a5b5c9e5887b2dff1c58159d614d5ffe32",
    "repro/proof/fixed_attempt2/response.headers": "9e56a901ad81037a8ab71c96469463484d0c7228fb4abe3d610f56f8dc0b65fc",
    "repro/proof/fixed_attempt2/http_status.txt": "c11e3f4837efde2441e23a7b9da02131f53bf59fddeb7147c4ab81afe400460f",
    "repro/proof/fixed_attempt2/server.log": "89877d4ed2ccb380ea15804813b291eee8952eefbe3ca5b055a56464ec11dd42",
    "repro/proof/fixed_attempt2/observation.json": "c5f642c5fad045eef0af3e3676b84a1ce57372cb853e071f00d21e7ce3708567",
    "repro/proof/fixed_attempt2/response.body": "0637e322456647ccfbecd7ba368c9b4b017110d8dd3a45c3fffdaad9815ce34b"
  },
  "notes": "Two fresh vulnerable processes created exact unique command markers; two fixed 16.3.6 controls reached the same POST endpoint, returned HTTP 200 PNG responses, and created no marker. No sanitizer used."
}