28 CVEs affecting Sass-Lang products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Libsass, Node-Sass, Sassc.