{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "f719f7722f9728b70d103598bc86b5ed919b117d3c019f661204417b9f8ba201",
    "authored_runtime_manifest_sha256": "33995a9951d534c9489747ad338aaec9a49a5c2ab4dc8aec70bda06073e746e5",
    "authored_verdict_sha256": "7fbc27297fc7524372c8714fb553007e9ab2ecbbed58e0ccbe94390d13b593d1",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Crafted ODS containing a persisted calcext:data-mapping with provider org.libreoffice.calc.sql, calcext:id secretfile@<attacker-hosted odb URL>, xlink:href sdbc:flat:file://<victim folder>, and calcext:database-name naming an attacker-chosen destination range; the attacker-hosted odb names the victim's folder of local text files as a text/csv file-based database",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "viewer_document",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Document open in LibreOffice Calc -> ScXMLMappingContext restores the sql data mapping and refreshes it -> SQLFetchThread resolves the document-named database (attacker odb) via sdb::DatabaseContext -> sdbc:flat:file://<victim folder> connection (flat Text/CSV SDBC driver) -> SELECT * FROM secretfile -> local victim text file contents copied into the sheet (named database range)",
  "validated_surface": "viewer_document"
}
