CreateTransaction checks that recipient amounts aren't negative, but not that they're within MAX_MONEY. CreateTransactionInternal then sums them into recipients_sum (spend.cpp:1100) with no range check, and that sum can overflow.
Easiest way to hit it is fundrawtransaction with a raw tx that has two outputs of 2^62 sat. It can also be reached with only valid amounts through walletcreatefundedpsbt/send/sendmany and a few thousand 21M BTC outputs. The "Transaction too large" check only runs after coin selection, so it doesn't stop this. On master the node aborts:
Assertion failed: (!m_selected_inputs.empty()), function RecalculateWaste, file coinselection.cpp, line 904.
UBSan reports the overflow at spend.cpp:1100 first. With other values the sum wraps to a small positive number instead, and fundrawtransaction returns success for a tx with outputs of 46116860184 BTC each.
This checks every amount and the running sum against MoneyRange in CreateTransaction, next to the existing negative check, and returns an error before coin selection starts. The new test_outputs_above_max_money in wallet_fundrawtransaction.py covers a single output above MAX_MONEY, two outputs whose sum is above it, and a sum that overflows int64. On master the first case returns "Insufficient funds" and the overflow case crashes the node. With the fix all three get the new error. I ran it on a normal and an ASan/UBSan build, and wallet_basic.py and rpc_psbt.py still pass.