CVE-2025-62782
EPSS 0.02%InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
Published: 10/27/2025Modified: 10/27/2025
Description
### Impact Any plugin using the GuiStorageElement is impacted when used on a server which allows the (currently experimental) Bundle items. ### Patches Patched with https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494 ("backported" to 1.6.3-SNAPSHOT) Update to 1.6.4-SNAPSHOT to guarantee that it's included! ### Workarounds Don't enable the experiment "Bundle" items or don't use the GuiStorageElement in GUIs. ### References Original issue: https://github.com/Phoenix616/InventoryGui/issues/51
Affected packages (1)
- Maven/de.themoep:inventoryguifrom 0, < 1.6.4-SNAPSHOT
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:L/SA:L |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-62782
- PATCHhttps://github.com/Phoenix616/InventoryGui
- WEBhttps://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494
- WEBhttps://github.com/Phoenix616/InventoryGui/issues/51
- WEBhttps://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-rgvh-4m82-fvjq