Логотип exploitDog
bind:CVE-2025-58759
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-58759

Количество 2

Количество 2

nvd логотип

CVE-2025-58759

5 месяцев назад

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication. The issue is fixed in v1.0.11. Users should upgrade to the latest patched version. As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-72cm-7236-h43r

5 месяцев назад

TinyEnv: Inline comments not stripped properly in .env values

CVSS3: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-58759

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication. The issue is fixed in v1.0.11. Users should upgrade to the latest patched version. As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.

CVSS3: 5.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-72cm-7236-h43r

TinyEnv: Inline comments not stripped properly in .env values

CVSS3: 5.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу