TinyEnv did not properly strip inline comments inside .env values. This could lead to unexpected behavior or misconfiguration, where variables contain unintended characters (including # or comment text). Applications depending on strict environment values may expose logic errors, insecure defaults, or failed authentication.
Fixed in v1.0.11. Users should upgrade to the latest patched version.
As a temporary workaround, avoid using inline comments in .env files, or sanitize loaded values manually.
{
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2025-09-09T21:01:44Z",
"nvd_published_at": "2025-09-09T20:15:49Z",
"severity": "MODERATE"
}