PT-2025-44049 · Unknown · Inventorygui
Published
2025-10-27
·
Updated
2026-02-13
·
CVE-2025-62784
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
InventoryGui versions prior to 1.6.5
Description
InventoryGui is a library used for creating chest GUIs for Bukkit/Spigot plugins. A flaw exists in versions before 1.6.5 where item duplication can occur. This happens when a plugin utilizes a GUI with the
GuiStorageElement and allows items to be removed from that element, specifically when the server’s experimental Bundle item feature is enabled.Recommendations
Versions prior to 1.6.5 should be updated to version 1.6.5.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inventorygui