{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "b81f47cfe66d82492fb29aeb553fd6700972eaea16f4edd97419d7b31b81c6eb",
    "authored_runtime_manifest_sha256": "db6f610d50a5a8830f2fd79a8cc0c79635416d0295af1207d452c0401d318574",
    "authored_verdict_sha256": "2c589aa6cd57f54d0104d20af3fbc617d8955bc717ae03c0f358c93a0001242e",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "fd361375-6966-4374-a027-9be75458fb2c",
    "772c9636-66d9-4daa-b5cc-1afe3797681d",
    "a160f7f9-ce65-442d-a15d-95e5b749e024"
  ],
  "attacker_controlled_input": "JSON code field of POST /api/v1/validate/code (\"import <attacker-planted-module>\"), with the module planted remotely via the class body of POST /api/v1/custom_component; superuser JWT minted with no credentials via GET /api/v1/auto_login (LANGFLOW_AUTO_LOGIN=true package default)",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "POST /api/v1/validate/code -> lfx.custom.validate.validate_code() -> importlib.import_module(attacker_module) executes module top-level code in the server process (fixed in 1.12.3 by commit 461506ac2f, find_spec-only)",
  "validated_surface": "api_remote"
}
