CVE 5.3 MEDIUM

InventoryGui allows item duplication in GUIs which use GuiStorageElement_CVE-2025-62784

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Description

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.

Basic Information

ID CVE-2025-62784
Source GitHub_M
Published Oct 27, 2025 at 20:59

Affected Product

Vendor Phoenix616
Product InventoryGui
Version < 1.6.5
Affected Versions Phoenix616 InventoryGui < 1.6.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.