{"id":"GHSA-gj2h-2fpw-fhv9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gj2h-2fpw-fhv9","summary":"@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration","details":"### Summary\n\n`UForm` and `UAuthForm` render a server-side `<form>` element with no `method` and no `action` attribute, relying on a hydrated `@submit.prevent` handler to intercept submission. If a user submits the form before Vue hydration has attached the handler (autofill plus Enter on a slow network, JS bundle blocked by CSP or CDN failure, etc.), the browser performs the native default: a `GET` to the current URL with every named field, including `<input type=\"password\">`, serialised into the query string.\n\n### Details\n\n`src/runtime/components/Form.vue` (around the template's `<form>` element) emits:\n\n```vue\n<component\n  :is=\"parentBus ? 'div' : 'form'\"\n  :id=\"formId\"\n  ref=\"formRef\"\n  :class=\"ui({ class: [uiProp?.base, props.class] })\"\n  @submit.prevent=\"onSubmitWrapper\"\n>\n```\n\nNo `method`, no `action`. `@submit.prevent` is the only thing stopping native submission, and it only exists after hydration. `UAuthForm` composes `UForm` and inherits the same shape.\n\nThe SSR snapshot of `UAuthForm` (`test/components/__snapshots__/AuthForm.spec.ts.snap`) shows the rendered markup, with `<input type=\"password\" name=\"password\">` inside a `<form>` that has no `method`.\n\n### Proof of concept\n\nReported by @nimonian:\n\n1. Create a minimal Nuxt app with a `UAuthForm`.\n2. Build for production and visit in a browser with network throttling at 4G or slower.\n3. Enter credentials.\n4. Submit (or let autofill + Enter fire before hydration).\n\nThe URL becomes `/login?email=…&password=…`. Reproducible deterministically in Playwright by triggering submit immediately on `load`.\n\n### Impact\n\nAny application using `UAuthForm` (or `UForm` with credential-shaped fields) as documented. The cleartext password lands in:\n\n- the address bar,\n- `window.history`,\n- the `Referer` header of every same-origin subresource fetched from the resulting URL,\n- access logs of any reverse proxy, CDN, or WAF that records request URLs.\n\n### Patch\n\nDefault the rendered `<form>` to `method=\"post\"` so the pre-hydration fallback submits as POST rather than GET. Vue's `@submit.prevent` still intercepts the hydrated case; the attribute only matters in the race window. Applications that explicitly want native GET submission can opt back in by passing `method=\"get\"`.\n\n### Credit\n\nReported by @nimonian. Originally filed as `GHSA-92g7-2fpq-hmq8` against `nuxt/nuxt`; moved here because the affected code lives in `@nuxt/ui`.","published":"2026-07-02T20:16:12Z","modified":"2026-08-04T22:00:24.148635461Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nuxt/ui","fixedVersion":"4.8.1"}],"fix":{"url":"https://github.com/nuxt/ui/pull/6512","label":"nuxt/ui#6512"},"references":[{"type":"WEB","url":"https://github.com/nuxt/ui/security/advisories/GHSA-gj2h-2fpw-fhv9"},{"type":"WEB","url":"https://github.com/nuxt/ui/pull/6512"},{"type":"PACKAGE","url":"https://github.com/nuxt/ui"},{"type":"WEB","url":"https://github.com/nuxt/ui/releases/tag/v4.8.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-04T22:00:24.148635461Z"}}