CVE-2025-62783 Details
Description
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.2-SNAPSHOT.
A vulnerability allowing item duplication has been identified in the InventoryGui library, specifically in versions through 1.6.1-SNAPSHOT. This issue arises when the experimental Bundle item feature is enabled on the server, and any plugin utilizing the GuiStorageElement is affected. The duplication occurs by double-clicking on items that occupy multiple slots, which triggers a NullPointerException and facilitates the duplication process.
Update to InventoryGui version 1.6.2-SNAPSHOT, which addresses the vulnerability. If the updated version is not available, as a temporary measure, avoid using the GuiStorageElement in GUIs.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-837 | Improper Enforcement of a Single, Unique Action | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| phoenix616 inventorygui | < 1.6.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | Initial Analysis | [email protected] |
| Oct 27, 2025 | New CVE Received | [email protected] |