{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "6b49f6ff83773531dcc6f0e72917a5061e7444711a5f8903a44383412983ebc8",
    "authored_runtime_manifest_sha256": "ba86bf5be0211d3a2914174346769c15e70bb344f8332247601858954e1570f3",
    "authored_verdict_sha256": "33143869ff963d8e38c2378dfa418973ff7ffdd21591669ca52de8a3099a3f3a",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "93790da0-e0c8-4822-beb2-aa1e5a299262",
    "75e43b7c-4907-4ed8-b620-79465774de5e"
  ],
  "attacker_controlled_input": "SQL statements from an unprivileged LOGIN role: masking rules (SECURITY LABEL FOR anon ... MASKED WITH FUNCTION ...) embedding a custom operator, a domain cast and a view subquery that hide attacker-defined plpgsql payloads",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "unprivileged role declares masking rules -> extension superuser runs anon.anonymize_table() (static masking) -> masking expressions evaluated in superuser security context -> attacker plpgsql executes COPY TO PROGRAM (OS command) and ALTER ROLE ... SUPERUSER",
  "validated_surface": "api_remote"
}
