{"id":"GHSA-rgvh-4m82-fvjq","summary":"InventoryGui allows item duplication with experimental \"Bundle\" item in GUIs which use GuiStorageElement","details":"### Impact\nAny plugin using the GuiStorageElement is impacted when used on a server which allows the (currently experimental) Bundle items.\n\n### Patches\nPatched with https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494 (\"backported\" to 1.6.3-SNAPSHOT)\n\nUpdate to 1.6.4-SNAPSHOT to guarantee that it's included!\n\n### Workarounds\nDon't enable the experiment \"Bundle\" items or don't use the GuiStorageElement in GUIs.\n\n### References\nOriginal issue: https://github.com/Phoenix616/InventoryGui/issues/51","aliases":["CVE-2025-62782"],"modified":"2025-10-27T22:32:04Z","published":"2025-10-27T20:12:50Z","database_specific":{"nvd_published_at":"2025-10-27T21:15:38Z","cwe_ids":["CWE-837"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-27T20:12:50Z"},"references":[{"type":"WEB","url":"https://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-rgvh-4m82-fvjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62782"},{"type":"WEB","url":"https://github.com/Phoenix616/InventoryGui/issues/51"},{"type":"WEB","url":"https://github.com/Phoenix616/InventoryGui/commit/00e684bd689ebc60bcb5b83ce4ef3c5a01778494"},{"type":"PACKAGE","url":"https://github.com/Phoenix616/InventoryGui"}],"affected":[{"package":{"name":"de.themoep:inventorygui","ecosystem":"Maven","purl":"pkg:maven/de.themoep/inventorygui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.4-SNAPSHOT"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.6.3-SNAPSHOT","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-rgvh-4m82-fvjq/GHSA-rgvh-4m82-fvjq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:L/SA:L"}]}