{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "1a6bf5f5c8d8b9a998dae112a88ae77bd348b6d22f3de9b8e68a52c79c1b15c0",
    "authored_runtime_manifest_sha256": "090c8a680f7f70238e032f6d7b824b99caec9dbc336533e70401fc4b40e85106",
    "authored_verdict_sha256": "c2b68e7038679b39539ccdc450190ba21eadf73a1af18fac78f0f32953e2c131",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "POST body parameter 'template' (user-editable template source) rendered via service('parser')->setData([...])->renderString($template)",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "POST /render -> App\\Controllers\\TemplateRender::render -> CodeIgniter\\View\\Parser::renderString -> parseConditionals() -> eval() of attacker-controlled {if} condition",
  "validated_surface": "api_remote"
}
