The file that hid URLs
A player that probes its files by content will also read what is disguised. A fake .mp3 holding an ffconcat manifest could make a local player open arbitrary URLs. The countermeasure fits in one option, and the lesson outgrows the case.
The flip side of content probing
AquaTube opens its media with FFmpeg, which identifies a file by probing it: it looks at the content, not the extension. That is its strength, and the right decision for a player; it is what makes badly named files play where other players refuse them.
The direct consequence: the extension no longer bounds anything. A file renamed "song.mp3" that actually contains something else entirely will be recognized for what it is, and treated as such. The capability that fixes honest files also serves disguised ones.
What a manifest may ask for
Among the formats FFmpeg recognizes by content, some are list formats: the ffconcat manifest, HLS playlists. Their entries are not sound, they are sources to open. Including network sources.
The scenario fits in one drag-and-drop: an "audio" file dropped on the pod, probed, recognized as a manifest, and the local player starts opening URLs chosen by the file's author, from the user's machine. A local file player was becoming a network client without anyone knowing. The hole was found in passing, during the decoder work of v0.16.0 (July 16, 2026), and here is the uncomfortable part: the already published versions of AquaTube were already going through FFmpeg for video, without the countermeasure. The fix was absent from the published builds.
One line, one boundary
The countermeasure is an open option: `protocol_whitelist=file`. A local file player only needs the file protocol; everything else is cut at the source. The disguised manifest is still recognized, still read, but every source it points to must be a local file: the pivot toward the network no longer exists.
Choosing a whitelist over a blacklist is not a detail. A blacklist of dangerous protocols requires knowing them all, today and in every future version of FFmpeg. The whitelist reverses the burden: it declares the one real need, and the unknown is forbidden by default.
What I take away
Probing by content remains the right decision; giving it up would have fixed the flaw by breaking the feature. The lesson is elsewhere: every powerful dependency ships with uses you never asked of it, and its default configuration is written for the general case, not yours.
The question to ask of every generic building block you integrate: what does it need for my precise use, and how do I cut off everything else. The answer often fits, as it did here, in one option set in the right place, with a comment explaining what it forbids.
The countermeasure has been live since the version published on July 16, 2026: the decoder accepts nothing but the file protocol. If you are running an earlier version, update.