CVE-2025-62782

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.4-SNAPSHOT.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phoenix616:inventorygui:*:*:*:*:*:*:*:*

History

04 Nov 2025, 13:23

Type Values Removed Values Added
First Time Phoenix616 inventorygui
Phoenix616
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:phoenix616:inventorygui:*:*:*:*:*:*:*:*
References () https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494 - () https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494 - Patch
References () https://github.com/Phoenix616/InventoryGui/issues/51 - () https://github.com/Phoenix616/InventoryGui/issues/51 - Issue Tracking
References () https://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-rgvh-4m82-fvjq - () https://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-rgvh-4m82-fvjq - Patch, Vendor Advisory

27 Oct 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 21:15

Updated : 2025-11-04 13:23


NVD link : CVE-2025-62782

Mitre link : CVE-2025-62782

CVE.ORG link : CVE-2025-62782


JSON object : View

Products Affected

phoenix616

  • inventorygui
CWE
CWE-837

Improper Enforcement of a Single, Unique Action