InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inventorygui
Inventorygui inventorygui |
|
| Vendors & Products |
Inventorygui
Inventorygui inventorygui |
Mon, 27 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5. | |
| Title | InventoryGui allows item duplication in GUIs which use GuiStorageElement | |
| Weaknesses | CWE-837 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-28T14:32:11.543Z
Reserved: 2025-10-22T18:55:48.008Z
Link: CVE-2025-62784
Updated: 2025-10-28T14:32:07.595Z
Status : Received
Published: 2025-10-27T21:15:38.593
Modified: 2025-10-27T21:15:38.593
Link: CVE-2025-62784
No data.