Executive brief
Lettermint is a Node.js library for sending transactional emails. When developers reuse a single email client instance to send multiple messages (a common pattern in password reset and notification flows), properties from previous emails—like recipient addresses and message content—are not cleared and can accidentally be sent to subsequent recipients. This could expose sensitive information or deliver messages to the wrong people.
Technical details
The vulnerability is a state management bug (CWE-488: Exposure of Data Element to Wrong Session) in the Lettermint Node.js SDK. When a client instance is reused across multiple .send() calls, email properties (to, subject, html, text, attachments) are not reset after each send, causing state from one message to carry over into the next. The attack requires local access and the ability to interact with the application code that calls the SDK, but no privileges or user interaction beyond that. An attacker with write access to the application or control over input parameters could craft sequences of sends that expose previous recipients or content. The issue was patched in version 1.5.1 with a fix that resets properties after each send operation.
Affected products
- Lettermint lettermint <1.5.1
Timeline
- 2026-02-20: disclosed: GHSA-49pc-8936-wvfp advisory published
- 2026-02-20: patched: Version 1.5.1 released with fix to reset email properties after send