Medium severity5.1NVD Advisory· Published Sep 9, 2025· Updated Jun 17, 2026
CVE-2025-58758
CVE-2025-58758
Description
TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the .env file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the .env file before initializing TinyEnv.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
datahihi1/tiny-envPackagist | < 1.0.3 | 1.0.3 |
datahihi1/tiny-envPackagist | >= 1.0.9, < 1.0.11 | 1.0.11 |
Affected products
3- datahihi1/tiny-envv5Range: >= 1.0.1, < 1.0.3
Patches
Vulnerability mechanics
References
5- github.com/datahihi1/tiny-env/commit/69b7b885e6cfbf07f470fb3512360e0caa95521envdPatchWEB
- github.com/advisories/GHSA-3j7m-5g4q-gfpcghsaADVISORY
- github.com/datahihi1/tiny-env/security/advisories/GHSA-3j7m-5g4q-gfpcnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-58758ghsaADVISORY
- github.com/datahihi1/tiny-env/commit/7dc656c58bef6050afb8f7a395e38227e31a66dfghsaWEB
News mentions
0No linked articles in our index yet.