Files
codeql/javascript/ql/test/query-tests/Security/CWE-776/libxml.noent.js
2025-02-28 13:27:28 +01:00

7 lines
224 B
JavaScript

const express = require('express');
const libxmljs = require('libxmljs');
express().get('/some/path', function(req) {
libxmljs.parseXml(req.param("some-xml"), { noent: true }); // $ Alert - unguarded entity expansion
});