{
 "entrypoint_kind": "open_document",
 "entrypoint_detail": "LibreOffice Calc opens a crafted ODS whose persisted calcext:data-mapping (org.libreoffice.calc.sql, id T@http://127.0.0.1:8379/evil.odb) is restored during load, fetches the attacker-hosted ODB over HTTP and attaches its embedded Firebird database; an ON CONNECT database trigger creates the Firebird nbackup difference file at the attacker-chosen path /home/vscode/CVE-2026-63266_PWNED.marker",
 "service_started": true,
 "healthcheck_passed": true,
 "target_path_reached": true,
 "runtime_stack": [
  "python-http-server(attacker)",
  "LibreOffice Calc 26.2.4.2 (vulnerable)/26.2.5.2 (fixed)",
  "calc sql data provider",
  "sdb::DatabaseContext",
  "sdbc:embedded:firebird",
  "bundled Firebird 3.0.14 engine"
 ],
 "target_identity": {
  "repository_url": "https://github.com/libreoffice/core",
  "commit_sha": "0229ac93fcf0d7cbc6376066c6f35021cef002dc",
  "target_digest": "3838a31c3dcfee9b95dd21cff3b683ce7a2998d5c0e884f111378af907077f7b",
  "platform": "linux",
  "architecture": "x86_64"
 },
 "proof_artifacts": [
  "repro/crafted/evil.ods",
  "repro/crafted/evil.odb",
  "repro/proof/vulnerable-1/soffice.log",
  "repro/proof/vulnerable-1/result.json",
  "repro/proof/vulnerable-1/marker.bin",
  "repro/proof/vulnerable-1/marker-strings.txt",
  "repro/proof/vulnerable-1/attacker-http-snapshot.log",
  "repro/proof/vulnerable-2/soffice.log",
  "repro/proof/vulnerable-2/result.json",
  "repro/proof/vulnerable-2/marker.bin",
  "repro/proof/vulnerable-2/marker-strings.txt",
  "repro/proof/vulnerable-2/attacker-http-snapshot.log",
  "repro/proof/fixed-1/soffice.log",
  "repro/proof/fixed-1/result.json",
  "repro/proof/fixed-1/attacker-http-snapshot.log",
  "repro/proof/fixed-2/soffice.log",
  "repro/proof/fixed-2/result.json",
  "repro/proof/fixed-2/attacker-http-snapshot.log"
 ],
 "artifact_sha256": {
  "repro/crafted/evil.ods": "2da69baa895994d81ba62395f743c27c3c47353a96eaf69f7488aa1b4b36a84e",
  "repro/crafted/evil.odb": "8698f3608ba5e34d66ee7839b277c9190beedc819390994e6cef2b9af35f8b2f",
  "repro/proof/vulnerable-1/soffice.log": "5c58d1e1cae2c56962b47f96ac7c762e91fceccd77ecde37a71b4c9eaaec3835",
  "repro/proof/vulnerable-1/result.json": "faca19dd90a2d767cdbf09186b28cf6f029b5924a6688d21c7a23d1cf14184d4",
  "repro/proof/vulnerable-1/marker.bin": "163ad51b66df5f13d42bd2ace8ae137526ecffe539a256e881e60a3113759d40",
  "repro/proof/vulnerable-1/marker-strings.txt": "56c67ae8bb747df421fc4c726bed753540b41c74eccbb1db9952ff0115a7c958",
  "repro/proof/vulnerable-1/attacker-http-snapshot.log": "ff7ab1b33dca899ae822815937ba9d719dcfaa49aa4ad376d81c273b0b17e0ef",
  "repro/proof/vulnerable-2/soffice.log": "5c58d1e1cae2c56962b47f96ac7c762e91fceccd77ecde37a71b4c9eaaec3835",
  "repro/proof/vulnerable-2/result.json": "b20d0f353cbfb72872f26d7449edc67b5ea1828e435fe215111d0f0ef4d58e8b",
  "repro/proof/vulnerable-2/marker.bin": "2d723ba589ea8f9a6a552a51d6b3b856947182f385bdc55692e477d769be6d9a",
  "repro/proof/vulnerable-2/marker-strings.txt": "a9db238b26b3cff2d8da51cd75d4c21efc15d24eb2f0f52a9fe78216449878b0",
  "repro/proof/vulnerable-2/attacker-http-snapshot.log": "d15db08d063bfb0cb10537d45da75bd4fca8361b6948d0dd5a23377393e9161b",
  "repro/proof/fixed-1/soffice.log": "f2bf660febd58fd3c2a24186e4c17636824fcb2aa0681b7ed3f6c0f6b04027f1",
  "repro/proof/fixed-1/result.json": "7a8abea125dd5b2eca488959a17103bed808de8c735a1f9abd563f047559687d",
  "repro/proof/fixed-1/attacker-http-snapshot.log": "d15db08d063bfb0cb10537d45da75bd4fca8361b6948d0dd5a23377393e9161b",
  "repro/proof/fixed-2/soffice.log": "83efdd7bbc97d2cf1a7a40e935b1dd3818d408d1bfd3a813524bac64845b0583",
  "repro/proof/fixed-2/result.json": "d9b1485fecb074ba7bc1f3e1f478ba88c4a76d077d218709b3ce0955c591e255",
  "repro/proof/fixed-2/attacker-http-snapshot.log": "d15db08d063bfb0cb10537d45da75bd4fca8361b6948d0dd5a23377393e9161b"
 },
 "notes": "vulnerable build: LibreOffice 26.2.4.2 0229ac93fcf0d7cbc6376066c6f35021cef002dc; fixed negative-control build: LibreOffice 26.2.5.2 cd7284b4cbbfeb507e630c1aac019f4157393acb (build commit cd7284b4cbbfeb507e630c1aac019f4157393acb); arbitrary write target: /home/vscode/CVE-2026-63266_PWNED.marker; verdict confirmed=True"
}