{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "93741e7e8e7a362bc8370daaec0e351c3dec96f8a06b90ea8dec2df539b2ec8c",
    "authored_runtime_manifest_sha256": "4b7ec875b9ee8ac4a27257159cab3fcf546f4191a12d6fd055458f2af76013b5",
    "authored_verdict_sha256": "6bd3843cd5f75a4965886343e50ab1902ecb166c24ded7ef01f129770416942a",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "0a5fcc52-9e7e-4c42-938c-637a1fa3e60e",
    "1ccd9188-d7f1-42e4-9c88-786b44795b0d",
    "3bafc17c-a577-43b6-b8a7-2ebfbeec2dd3",
    "59872765-1968-4048-bd13-b70e07f439b7",
    "62e60bee-16b0-4e49-8ddf-8e21662e02bd",
    "6d474f91-6206-47ab-9af8-f9a71be53478",
    "cfbfed73-974f-4605-814e-116de201f0f2"
  ],
  "attacker_controlled_input": "SQL arguments (strings, int32 ins/del/sub costs, max_d) to levenshtein_less_equal()/levenshtein() via contrib/fuzzystrmatch as a low-privilege authenticated role, plus heap grooming via held-cursor sprays of attacker-chosen bytes",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "library_api",
  "crash_observed": true,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "psql/libpq -> SQL levenshtein_less_equal -> varstr_levenshtein_less_equal int32 wraparound of stop_column -> prev[stop_column] OOB write -> AllocSet keeper/context metadata corruption -> directed free -> libc disclosure via cursor FETCH readback -> methods vtable hijack -> system() from the backend",
  "validated_surface": "library_api"
}
