VDB
Sign up
MEDIUM5.1

GHSA-72cm-7236-h43r

TinyEnv: Inline comments not stripped properly in .env values

Quick fix

GHSA-72cm-7236-h43r — datahihi1/tiny-env: upgrade to the fixed version with the command below.

composer require datahihi1/tiny-env:^1.0.11

Details

### Impact TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication.

### Patches Fixed in v1.0.11. Users should upgrade to the latest patched version.

### Workarounds As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/datahihi1/tiny-env
Introduced in: 1.0.9Fixed in: 1.0.11
Fixcomposer require datahihi1/tiny-env:^1.0.11

References