{"id":"GHSA-gj2h-2fpw-fhv9","title":"@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration","summary":"@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration","severity":"medium","cwe":["CWE-200","CWE-598"],"vendor":"nuxt","product":"@nuxt/ui","ecosystem":"npm","affected":["@nuxt/ui <= 4.7.1"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-gj2h-2fpw-fhv9","references":[{"url":"https://github.com/nuxt/ui/security/advisories/GHSA-gj2h-2fpw-fhv9"},{"url":"https://github.com/advisories/GHSA-gj2h-2fpw-fhv9"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T20:42:45.684Z","slug":"GHSA-gj2h-2fpw-fhv9","body":"## Overview\n\n### Summary\n\n`UForm` and `UAuthForm` render a server-side `<form>` element with no `method` and no `action` attribute, relying on a hydrated `@submit.prevent` handler to intercept submission. If a user submits the form before Vue hydration has attached the handler (autofill plus Enter on a slow network, JS bundle blocked by CSP or CDN failure, etc.), the browser performs the native default: a `GET` to the current URL with every named field, including `<input type=\"password\">`, serialised into the query string.\n\n### Details\n\n`src/runtime/components/Form.vue` (around the template's `<form>` element) emits:\n\n```vue\n<component\n  :is=\"parentBus ? 'div' : 'form'\"\n  :id=\"formId\"\n  ref=\"formRef\"\n  :class=\"ui({ class: [uiProp?.base, props.class] })\"\n  @submit.prevent=\"onSubmitWrapper\"\n>\n```\n\nNo `method`, no `action`. `@submit.prevent` is the only thing stopping native submission, and it only exists after hydration. `UAuthForm` composes `UForm` and inherits the same shape.\n\nThe SSR snapshot of `UAuthForm` (`test/components/__snapshots__/AuthForm.spec.ts.snap`) shows the rendered markup, with `<input type=\"password\" name=\"password\">` inside a `<form>` that has no `method`.\n\n### Proof of concept\n\nReported by @nimonian:\n\n1. Create a minimal Nuxt app with a `UAuthForm`.\n2. Build for production and visit in a browser with network throttling at 4G or slower.\n3. Enter credentials.\n4. Submit (or let autofill + Enter fire before hydration).\n\nThe URL becomes `/login?email=…&password=…`. Reproducible deterministically in Playwright by triggering submit immediately on `load`.\n\n### Impact\n\nAny application using `UAuthForm` (or `UForm` with credential-shaped fields) as documented. The cleartext password lands in:\n\n- the address bar,\n- `window.history`,\n- the `Referer` header of every same-origin subresource fetched from the resulting URL,\n- access logs of any reverse proxy, CDN, or WAF that records request URLs.\n\n### Patch\n\nDefault the rendered `<form>` to `method=\"post\"` so the pre-hydration fallback submits as POST rather than GET. Vue's `@submit.prevent` still intercepts the hydrated case; the attribute only matters in the race window. Applications that explicitly want native GET submission can opt back in by passing `method=\"get\"`.\n\n### Credit\n\nReported by @nimonian. Originally filed as `GHSA-92g7-2fpq-hmq8` against `nuxt/nuxt`; moved here because the affected code lives in `@nuxt/ui`.\n\n## Affected packages\n\n- `@nuxt/ui <= 4.7.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}