From 0955739fc404fbb048002920bdaec2d3e469308d Mon Sep 17 00:00:00 2001 From: amit kumar gupta Date: Tue, 6 Jun 2023 06:18:11 +0530 Subject: [PATCH] fix: security bug --- src/xmlparser/DocTypeReader.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/xmlparser/DocTypeReader.js b/src/xmlparser/DocTypeReader.js index 3b0fe05e..a144ade8 100644 --- a/src/xmlparser/DocTypeReader.js +++ b/src/xmlparser/DocTypeReader.js @@ -142,7 +142,7 @@ function isNotation(xmlData, i){ //an entity name should not contains special characters that may be used in regex //Eg !?\\\/[]$%{}^&*()<> -const specialChar = "!?\\\/[]$%{}^&*()<>"; +const specialChar = "!?\\\/[]$%{}^&*()<>|+"; function validateEntityName(name){ for (let i = 0; i < specialChar.length; i++) {