Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rgvh-4m82-fvjq | InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement |
Tue, 04 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phoenix616
Phoenix616 inventorygui |
|
| CPEs | cpe:2.3:a:phoenix616:inventorygui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phoenix616
Phoenix616 inventorygui |
|
| Metrics |
cvssV3_1
|
Tue, 28 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inventorygui
Inventorygui inventorygui |
|
| Vendors & Products |
Inventorygui
Inventorygui inventorygui |
Mon, 27 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.4-SNAPSHOT. | |
| Title | InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement | |
| Weaknesses | CWE-837 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-28T14:33:18.973Z
Reserved: 2025-10-22T18:55:48.008Z
Link: CVE-2025-62782
Updated: 2025-10-28T14:32:36.364Z
Status : Analyzed
Published: 2025-10-27T21:15:38.287
Modified: 2025-11-04T13:23:24.003
Link: CVE-2025-62782
No data.
OpenCVE Enrichment
Updated: 2025-10-28T10:24:18Z
Github GHSA