GHSA-3j7m-5g4q-gfpc
TinyEnv: Missing .env file not required — may cause unexpected behavior
Quick fix
GHSA-3j7m-5g4q-gfpc — datahihi1/tiny-env: upgrade to the fixed version with the command below.
composer require datahihi1/tiny-env:^1.0.3Details
### Impact TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to **unexpected behavior** where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations.
Affected versions: - **1.0.1 → 1.0.2** - **1.0.9 → 1.0.10**
### Patches The issue has been fixed in **version 1.0.11**. All users should upgrade to `1.0.11` or later.
### Workarounds As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv, for example:
```php if (!file_exists(__DIR__ . '/.env')) { throw new RuntimeException('.env file is missing!'); }
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.3composer require datahihi1/tiny-env:^1.0.31.0.9Fixed in: 1.0.11composer require datahihi1/tiny-env:^1.0.11References
- https://github.com/datahihi1/tiny-env/security/advisories/GHSA-3j7m-5g4q-gfpc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-58758[ADVISORY]
- https://github.com/datahihi1/tiny-env/commit/69b7b885e6cfbf07f470fb3512360e0caa95521e[WEB]
- https://github.com/datahihi1/tiny-env/commit/7dc656c58bef6050afb8f7a395e38227e31a66df[WEB]
- https://github.com/datahihi1/tiny-env[PACKAGE]