{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "7a5f3f9fb777bc20a1ca3c7a86031e3e7d5a6712fc8327d419fb421846427e72",
    "authored_runtime_manifest_sha256": "8e4c7b57bbe4e9c8c633e23496a6a5cf055abe493e260a1960422ebb6c21cc54",
    "authored_verdict_sha256": "cb46a2e09888c8225623a846dc9520bbd70967a6f0e1fd89041871293a2f4129",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "3f4a24f2-16c9-498a-a22b-a5d2874f4930",
    "29471ddd-389e-447a-b142-7a47469b2054"
  ],
  "attacker_controlled_input": "Unauthenticated POST /api/og text body containing a command-specific Rasterfall SVG/XInclude/path payload in SVG <title> content",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Next.js next start App Router endpoint -> Node.js next/og ImageResponse -> vulnerable Satori SVG serialization -> sharp 0.35.4/libvips 8.18.6/librsvg 2.62.91/libxml2 2.15.3 native renderer -> attacker-selected /bin/sh -c command",
  "validated_surface": "api_remote"
}
