CVE-2025-58758

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-58758
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-58758.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-58758
Aliases
Published
2025-09-09T20:15:49Z
Modified
2025-09-12T09:02:09.744248Z
Summary
[none]
Details

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the .env file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the .env file before initializing TinyEnv.

References

Affected packages

Git / github.com/datahihi1/tiny-env

Affected ranges

Type
GIT
Repo
https://github.com/datahihi1/tiny-env
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9