CVE-2025-62784
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
- EPSS probability
- 0.21%
- CWE
- CWE-837
- Published
- 2025-10-27
- Last modified
- 2026-03-13
Affected products
- Phoenix616 InventoryGui
Weakness type
Related vulnerabilities
- CVE-2026-86198 — PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket
- CVE-2026-45734 — MyBB: Default CAPTCHA missing invalidation
- CVE-2026-42609 — Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
- CVE-2026-44601 — Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash...
- CVE-2025-62783 — InventoryGui affected by item duplication in GUIs which use GuiStorageElement
- CVE-2025-62782 — InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement
- CVE-2025-54315 — The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event...
- CVE-2025-58135 — Zoom Workplace Clients for Windows - Improper Action Enforcement