---
id: CVE-2025-62784
title: InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins
summary: >-
  InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins.
  Versions before 1.6.5 contain a vulnerability where any plugin using a GUI
  with the GuiStorageElement and allows taking out items out of that element can
  allow …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-837
vendor: phoenix616
product: inventorygui
affected:
  - inventorygui < 1.6.5
patched:
  - inventorygui 1.6.5
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62784'
references:
  - url: >-
      https://github.com/Phoenix616/InventoryGui/commit/690fc91d137c6cc04f6ed3a89449050964dd8cb9
    label: security-advisories@github.com
  - url: >-
      https://github.com/Phoenix616/InventoryGui/security/advisories/GHSA-7whh-79j3-7c55
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00223
epssPercentile: 0.11887
ingestedAt: '2026-10-08T11:31:27.651Z'
---

## Overview

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.

## Affected

- `inventorygui < 1.6.5`

## Remediation

Upgrade past the affected range:

- `inventorygui 1.6.5`
