unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
CVSS Metrics