Lettermint is a focused mail and document delivery platform where the durable vulnerability signal centers on session-management handling in its core product. The observed weakness class, exposure of data elements to wrong sessions, reflects the session-isolation and state-management demands inherent to a multi-tenant communications service. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lettermint over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27492MEDIUM Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset be | Feb 21, 2026 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lettermint.
Media articles that mention a CVE ID that affects a product developed by Lettermint — matched by CVE ID, not by vendor name.