An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
https://github.com/advisories/GHSA-qfjv-998w-q48f
https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions