doing curl http://localhost:3000/forward?q=http://some.location.of.mjpeg.stream/stream.mjpeg
definitely does the incorrect thing when dealing with mjpeg streams
This is also most likely an issue when using large files too.
For mjpegs it can in theory work by reading the first frame...
For large files there should be a cap to the request...
possible exploit: somebody could use a public VMX node to redirect traffic somewhere else using /forward
possible exploit: somebody could overwhelm VMX by sending it many many /forward requests to motionjpegs