My favorite bug class right now: **argument injection.** 🎯
Jellyfin had an unauthenticated endpoint that could turn FFmpeg into a file reader.
📍 `/Videos/{itemId}/stream`
An unvalidated query parameter was passed straight into FFmpeg.
The trick wasn't `;id` or shell injection. ❌
It was an `-vf drawtext` filter that made FFmpeg render `[/]etc[/]shadow` into the video response. 👀
✅ No shell needed
✅ No semicolon
💀 Just argument injection.