CVE-2026-27492
Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset between sends when a single client instance is reused across multiple .send() calls. This can cause properties from a previous send to leak into a subsequent one, potentially delivering content or recipient addresses to unintended parties. Applications sending emails to different recipients in sequence — such as transactional flows like password resets or notifications — are affected. This issue has been fixed in version 1.5.1.
Published:Feb 21, 2026
Last Modified:Apr 18, 2026
EPS:Feb 21, 2026
EPSS Score:0.00006
CVSS Score:4.7
Affected Products
Vendor
Product
Action
Vendor
Lettermint
Product
Lettermint
Lettermint
Lettermint
Vendor
Lettermint
Product
Lettermint-node
Lettermint
Lettermint-node
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
