← Back

CVE-2025-58758

nvd nist
Published: Sep 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to unexpected behavior where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations. The issue has been fixed in version 1.0.11. All users should upgrade to 1.0.11 or later. As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv.

Affected (2)

Products: Datahihi1: Tinyenv
1 product
Tinyenv
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Datahihi1
From 1.0.1 to 1.0.3
From 1.0.9 to 1.0.11

References (2)

Timeline

No history available yet.