TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication. The issue is fixed in v1.0.11. Users should upgrade to the latest patched version. As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.
History

Tue, 09 Sep 2025 20:00:00 +0000

Type Values Removed Values Added
Description TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication. The issue is fixed in v1.0.11. Users should upgrade to the latest patched version. As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.
Title TinyEnv: Inline comments not stripped properly in .env values
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-09T19:52:39.014Z

Updated: 2025-09-10T20:15:16.418Z

Reserved: 2025-09-04T19:18:09.500Z

Link: CVE-2025-58759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-09T20:15:49.367

Modified: 2025-09-09T20:15:49.367

Link: CVE-2025-58759

cve-icon Redhat

No data.