CVE-2025-62782

Source
https://cve.org/CVERecord?id=CVE-2025-62782
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62782.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62782
Aliases
Published
2025-10-27T20:50:07Z
Modified
2026-08-12T15:14:33Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:L/SA:L CVSS Calculator
Summary
InventoryGUI vulnerable to item duplication via Bundle items when using GuiStorageElement
Details

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.4-SNAPSHOT.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-837"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62782.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "1.6.4-SNAPSHOT"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/phoenix616/inventorygui

Affected ranges

Type
GIT
Repo
https://github.com/phoenix616/inventorygui
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62782.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "145666348224457169577786363403626018755",
                "311816063490963696316923048496413969947",
                "257607004341042734467718713882600346852",
                "232723257273469902966993632982184475534",
                "295361484767764038626680623991642539786",
                "235418723405078612679866754834593741372",
                "162185252850738148297954695806917686882",
                "121685592874858552632345617394638618408"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2025-62782-073fba43",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/phoenix616/inventorygui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494",
        "target":  {
            "file":  "src/main/java/de/themoep/inventorygui/GuiStorageElement.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "174944923324403684357817921654350894557",
            "length":  4016
        },
        "id":  "CVE-2025-62782-d9124177",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/phoenix616/inventorygui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494",
        "target":  {
            "file":  "src/main/java/de/themoep/inventorygui/GuiStorageElement.java",
            "function":  "GuiStorageElement"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:14:33Z"