TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv.
History

Wed, 08 Oct 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Datahihi1
Datahihi1 tinyenv
CPEs cpe:2.3:a:datahihi1:tinyenv:*:*:*:*:*:*:*:*
Vendors & Products Datahihi1
Datahihi1 tinyenv

Wed, 10 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 20:00:00 +0000

Type Values Removed Values Added
Description TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv.
Title TinyEnv: Missing .env file not required — may cause unexpected behavior
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-10T20:14:26.393Z

Reserved: 2025-09-04T19:18:09.500Z

Link: CVE-2025-58758

cve-icon Vulnrichment

Updated: 2025-09-10T20:14:22.121Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T20:15:49.177

Modified: 2025-10-08T20:53:57.603

Link: CVE-2025-58758

cve-icon Redhat

No data.