{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "POST /render -> App\\Controllers\\TemplateRender::render -> service('parser')->setData([...])->renderString($attacker_template)",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "php-cli",
    "codeigniter4 spark serve (PHP built-in web server)"
  ],
  "target_identity": {
    "repository_url": "https://github.com/codeigniter4/CodeIgniter4.git",
    "commit_sha": "2bd0f01d2813f9ec06db42643ce39d9f5428bf6d",
    "target_digest": "4f84dd08702d8efbeca87473502cd1dfbcd32b0769cbabf169466107f7c49058",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "logs/vuln_server.log",
    "logs/fixed_server.log",
    "artifacts/http/vuln1_request.txt",
    "artifacts/http/vuln1_response.txt",
    "artifacts/http/vuln2_response.txt",
    "artifacts/http/fixedr1_response.txt",
    "artifacts/http/fixedr2_response.txt",
    "artifacts/http/fixedu1_response.txt",
    "artifacts/http/fixedu2_response.txt",
    "repro/markers/vuln1.txt",
    "repro/markers/vuln2.txt",
    "repro/markers/fixedu1.txt",
    "repro/markers/fixedu2.txt"
  ],
  "artifact_sha256": {
    "logs/vuln_server.log": "a3e7b31b083f2c8dd79ba491c7046efd9ef2293809aefb13e700455f24f8fbeb",
    "logs/fixed_server.log": "2e5ed5e562c2a4617e199a3c8e94890ab2e477d8ed0d7fc0ade6498bae18fc80",
    "artifacts/http/vuln1_request.txt": "2fbe9034a5b52a72a4db41d5ebaf05d4d0cc8a6979ed47737859a26d52f07d55",
    "artifacts/http/vuln1_response.txt": "98568ecacd9cee8004ba20182fdaaf4ae83ea2ff46960ee69a987aadd80e0800",
    "artifacts/http/vuln2_response.txt": "98568ecacd9cee8004ba20182fdaaf4ae83ea2ff46960ee69a987aadd80e0800",
    "artifacts/http/fixedr1_response.txt": "eba1c73a68a5a6194e89a1fc6243f2f78830065439d2986e7bac3e2c7f55481f",
    "artifacts/http/fixedr2_response.txt": "b219749479d288a666d9d577e73c5995a6977aaf451a9dd4815d01688c49c793",
    "artifacts/http/fixedu1_response.txt": "98568ecacd9cee8004ba20182fdaaf4ae83ea2ff46960ee69a987aadd80e0800",
    "artifacts/http/fixedu2_response.txt": "98568ecacd9cee8004ba20182fdaaf4ae83ea2ff46960ee69a987aadd80e0800",
    "repro/markers/vuln1.txt": "093447c75cc5623ccf5b3b2669e230db76c673e5af775567c5dffd5ca118efe3",
    "repro/markers/vuln2.txt": "b0d8efd5323104a25e958ee9a04becfd3f67d281f74ed7f47eff8eebb58ab716",
    "repro/markers/fixedu1.txt": "f63b10ba8637653a92d6833627f7c480316c5f23d703026a1a88051b21175b39",
    "repro/markers/fixedu2.txt": "215a1d0456e72c78fe19164d3e1faca56156d6f01be11c008ed643c06e4b483c"
  },
  "notes": "v4.7.4 eval()s attacker {if} condition as PHP -> marker files written and shell_exec('id') output returned over HTTP; v4.7.5 with restrictConditionals=true throws ViewException::forRestrictedConditional; v4.7.5 default (unrestricted) remains exploitable per advisory."
}