InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
Moderate severity
GitHub Reviewed
Published
Oct 21, 2024
in
Phoenix616/InventoryGui
•
Updated Oct 27, 2025
Package
Affected versions
<= 1.6.3-SNAPSHOT
Patched versions
1.6.4-SNAPSHOT
Description
Published to the GitHub Advisory Database
Oct 27, 2025
Reviewed
Oct 27, 2025
Published by the National Vulnerability Database
Oct 27, 2025
Last updated
Oct 27, 2025
Impact
Any plugin using the GuiStorageElement is impacted when used on a server which allows the (currently experimental) Bundle items.
Patches
Patched with Phoenix616/InventoryGui@00e684b ("backported" to 1.6.3-SNAPSHOT)
Update to 1.6.4-SNAPSHOT to guarantee that it's included!
Workarounds
Don't enable the experiment "Bundle" items or don't use the GuiStorageElement in GUIs.
References
Original issue: Phoenix616/InventoryGui#51
References