icon

We found results for “

CVE-2025-58758

Good to know:

icon
icon

Date: September 9, 2025

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the ".env" file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the ".env" file before initializing TinyEnv.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Check or Handling of Exceptional Conditions

CWE-703

Top Fix

icon

Upgrade Version

Upgrade to version datahihi1/tiny-env - null;datahihi1/tiny-env - 1.0.11

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us