CVE-2025-62784General(phoenix616 / inventorygui)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-837

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inventorygui

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
inventorygui

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-13: 102-13
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • transilienceai@transilienceai
    General

    Related 2025 CVEs (e.g., CVE-2025-62784 in inventorygui, CVE-2025-59837 in Astro) appear for other software. The query references a social media post claiming use of Claude Code (likely Anthropic's Claude model with coding capabilities) to reverse-engineer Codex's Mac App. #AI #TechNews 💻

    Post summary

    The text merely references a few 2025 CVEs and a social media claim that AI was used to reverse‑engineer an app, without providing technical or exploit details.

    1000081
    315 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphoenix616inventorygui---

Explore more