{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "22aee244824af16f901c96e817ed61cb909b4ba2693a311c0a46da35e9487015",
    "authored_runtime_manifest_sha256": "7e5d56700d9613ab8dacd5993ce68602a20a1b7a825d022d7309015a2528b3c6",
    "authored_verdict_sha256": "ac7fec341a082c33d5efb9e5b2009852b18c3fc8b5cea007980cc2defb722348",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "crafted .fods document with calcext:data-mapping entries whose xlink:href URLs are vnd.sun.star.expand:-wrapped http URLs carrying ${PRUVA63270_SECRET} and ${file:///<dir>/secret.ini:Secrets:Token} macros",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "viewer_document",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "LibreOffice Calc opens the crafted .fods -> ODF import ScXMLMappingContext -> ExternalDataSource::refresh -> CSVDataProvider -> DataProvider::FetchStreamFromURL (no scheme check) -> UCB ExpandContentProvider expands env/INI macros -> HTTP fetch delivers the victim's secret values to the attacker-controlled server",
  "validated_surface": "viewer_document"
}
