mirror of
https://github.com/github/codeql.git
synced 2025-12-17 17:23:36 +01:00
8 lines
224 B
JavaScript
8 lines
224 B
JavaScript
const express = require('express');
|
|
const libxmljs = require('libxmljs');
|
|
|
|
express().get('/some/path', function(req) {
|
|
// NOT OK: unguarded entity expansion
|
|
libxmljs.parseXml(req.param("some-xml"), { noent: true });
|
|
});
|