{"id":"CVE-2025-62782","aliases":["GHSA-rgvh-4m82-fvjq"],"url":"https://o3.security/vulnerability/CVE-2025-62782","summary":"InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement","details":"### Impact\nAny plugin using the GuiStorageElement is impacted when used on a server which allows the (currently experimental) Bundle items.\n\n### Patches\nPatched with https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494 (\"backported\" to 1.6.3-SNAPSHOT)\n\nUpdate to 1.6.4-SNAPSHOT to guarantee that it's included!\n\n### Workarounds\nDon't enable the experiment \"Bundle\" items or don't use the GuiStorageElement in GUIs.\n\n### References\nOriginal issue: https://github.com/Phoenix616/InventoryGui/issues/51","published":"2025-10-27T20:50:07.579Z","modified":"2026-08-12T15:14:33.855260Z","cvss":null,"epss":{"score":0.00243,"percentile":0.1527,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"de.themoep:inventorygui","fixedVersion":"1.6.4-SNAPSHOT"}],"fix":{"url":"https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494","label":"Phoenix616/InventoryGui@00e684b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62782.json"},{"type":"ADVISORY","url":"https://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-rgvh-4m82-fvjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62782"},{"type":"REPORT","url":"https://github.com/Phoenix616/InventoryGui/issues/51"},{"type":"FIX","url":"https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494"},{"type":"PACKAGE","url":"https://github.com/Phoenix616/InventoryGui"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:14:33.855260Z"}}