PT-2025-44049 · Unknown · Inventorygui

Published

2025-10-27

·

Updated

2026-02-13

·

CVE-2025-62784

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions InventoryGui versions prior to 1.6.5
Description InventoryGui is a library used for creating chest GUIs for Bukkit/Spigot plugins. A flaw exists in versions before 1.6.5 where item duplication can occur. This happens when a plugin utilizes a GUI with the GuiStorageElement and allows items to be removed from that element, specifically when the server’s experimental Bundle item feature is enabled.
Recommendations Versions prior to 1.6.5 should be updated to version 1.6.5.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-62784
GHSA-7WHH-79J3-7C55

Affected Products

Inventorygui