{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "d78b6a95433457acb2dc041276b53ba80b041506aa947e6d968749477678de4d",
    "authored_runtime_manifest_sha256": "5a4a7af90da085bb8394b4562c402742b88f27d60779235446d925d8ef638712",
    "authored_verdict_sha256": "8104019de1331f802cdb24dc4d9a9eb35c1cb8275689978dc246c9b7501076bf",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Crafted ODP document whose linked media (draw:plugin) URL points to an attacker-hosted HLS playlist listing a local file:// path and a remote http:// URL",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "ssrf",
  "claimed_surface": "viewer_document",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "ssrf",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "soffice open -> Impress media shape -> avmedia GStreamer playbin -> hlsdemux follows playlist URIs (souphttpsrc GET + filesrc local read)",
  "validated_surface": "viewer_document"
}
