{"id":"GHSA-72cm-7236-h43r","summary":"TinyEnv: Inline comments not stripped properly in .env values","details":"### Impact\nTinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication.\n\n### Patches\nFixed in v1.0.11. Users should upgrade to the latest patched version.\n\n### Workarounds\nAs a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.","aliases":["CVE-2025-58759"],"modified":"2025-09-10T21:56:17.423263Z","published":"2025-09-09T21:01:44Z","database_specific":{"nvd_published_at":"2025-09-09T20:15:49Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-09-09T21:01:44Z"},"references":[{"type":"WEB","url":"https://github.com/datahihi1/tiny-env/security/advisories/GHSA-72cm-7236-h43r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58759"},{"type":"WEB","url":"https://github.com/datahihi1/tiny-env/commit/69b7b885e6cfbf07f470fb3512360e0caa95521e"},{"type":"PACKAGE","url":"https://github.com/datahihi1/tiny-env"}],"affected":[{"package":{"name":"datahihi1/tiny-env","ecosystem":"Packagist","purl":"pkg:composer/datahihi1/tiny-env"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.9"},{"fixed":"1.0.11"}]}],"versions":["1.0.10","1.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-72cm-7236-h43r/GHSA-72cm-7236-h43r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}