VDB
Sign up
MEDIUM5.1

GHSA-3j7m-5g4q-gfpc

TinyEnv: Missing .env file not required — may cause unexpected behavior

Quick fix

GHSA-3j7m-5g4q-gfpc — datahihi1/tiny-env: upgrade to the fixed version with the command below.

composer require datahihi1/tiny-env:^1.0.3

Details

### Impact TinyEnv did not require the `.env` file to exist when loading environment variables. This could lead to **unexpected behavior** where the application silently ignores missing configuration, potentially causing insecure defaults or deployment misconfigurations.

Affected versions: - **1.0.1 → 1.0.2** - **1.0.9 → 1.0.10**

### Patches The issue has been fixed in **version 1.0.11**. All users should upgrade to `1.0.11` or later.

### Workarounds As a workaround, users can manually verify the existence of the `.env` file before initializing TinyEnv, for example:

```php if (!file_exists(__DIR__ . '/.env')) { throw new RuntimeException('.env file is missing!'); }

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/datahihi1/tiny-env
Introduced in: 0Fixed in: 1.0.3
Fixcomposer require datahihi1/tiny-env:^1.0.3
Packagist/datahihi1/tiny-env
Introduced in: 1.0.9Fixed in: 1.0.11
Fixcomposer require datahihi1/tiny-env:^1.0.11

References