TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv.
History

Tue, 09 Sep 2025 20:00:00 +0000

Type Values Removed Values Added
Description TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv.
Title TinyEnv: Missing .env file not required — may cause unexpected behavior
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-09T19:50:18.518Z

Updated: 2025-09-10T20:14:26.393Z

Reserved: 2025-09-04T19:18:09.500Z

Link: CVE-2025-58758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-09T20:15:49.177

Modified: 2025-09-09T20:15:49.177

Link: CVE-2025-58758

cve-icon Redhat

No data.