{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "731347e8a1fbae08092324c1de5c18ec87ac288d219f0020d59fe178ae43cbdb",
    "authored_runtime_manifest_sha256": "991e22508936fca2f6efb4367d9a21cc80de85aa5ed5a7c36e22d724ccd9ba90",
    "authored_verdict_sha256": "622fedf07863105467f590180a93bcb3a7c0df496770945dec7ea8b722fb5bb8",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "276f4f75-4636-4175-ac26-03941d71c6ff",
    "5cc3f0c6-2cc9-4b4b-bd75-492258f9b420"
  ],
  "attacker_controlled_input": "Authenticated Project scm_url beginning with --upload-pack= and an attacker-selected shell command",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "POST /api/v2/projects/ then POST /api/v2/projects/<id>/update/; AWX ProjectUpdate -> ansible Git module -> git ls-remote --upload-pack",
  "validated_surface": "api_remote"
}
