PT-2026-21340 · Unknown · Lettermint Node.Js Sdk

Bjarn

·

Publicado

2026-02-20

·

Atualizado

2026-02-24

·

CVE-2026-27492

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lettermint Node.js SDK versions 1.5.0 and below
Description The Lettermint Node.js SDK has an issue where email properties (to, subject, html, text, and attachments) are not reset between calls to the .send() function when the same client instance is reused. This can lead to data from a previous email being included in a subsequent email, potentially sending content or recipient addresses to unintended parties. Applications that send emails to different recipients sequentially, such as those used for password resets or notifications, are particularly susceptible. The issue occurs when reusing a single client instance across multiple .send() calls.
Recommendations Upgrade to version 1.5.1 or later. If upgrading is not immediately possible, create a new client instance for each .send() call.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27492
GHSA-49PC-8936-WVFP

Produtos afetados

Lettermint Node.Js Sdk