{"id":"GHSA-gj2h-2fpw-fhv9","summary":"@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration","details":"### Summary\n\n`UForm` and `UAuthForm` render a server-side `\u003cform\u003e` element with no `method` and no `action` attribute, relying on a hydrated `@submit.prevent` handler to intercept submission. If a user submits the form before Vue hydration has attached the handler (autofill plus Enter on a slow network, JS bundle blocked by CSP or CDN failure, etc.), the browser performs the native default: a `GET` to the current URL with every named field, including `\u003cinput type=\"password\"\u003e`, serialised into the query string.\n\n### Details\n\n`src/runtime/components/Form.vue` (around the template's `\u003cform\u003e` element) emits:\n\n```vue\n\u003ccomponent\n  :is=\"parentBus ? 'div' : 'form'\"\n  :id=\"formId\"\n  ref=\"formRef\"\n  :class=\"ui({ class: [uiProp?.base, props.class] })\"\n  @submit.prevent=\"onSubmitWrapper\"\n\u003e\n```\n\nNo `method`, no `action`. `@submit.prevent` is the only thing stopping native submission, and it only exists after hydration. `UAuthForm` composes `UForm` and inherits the same shape.\n\nThe SSR snapshot of `UAuthForm` (`test/components/__snapshots__/AuthForm.spec.ts.snap`) shows the rendered markup, with `\u003cinput type=\"password\" name=\"password\"\u003e` inside a `\u003cform\u003e` that has no `method`.\n\n### Proof of concept\n\nReported by @nimonian:\n\n1. Create a minimal Nuxt app with a `UAuthForm`.\n2. Build for production and visit in a browser with network throttling at 4G or slower.\n3. Enter credentials.\n4. Submit (or let autofill + Enter fire before hydration).\n\nThe URL becomes `/login?email=…&password=…`. Reproducible deterministically in Playwright by triggering submit immediately on `load`.\n\n### Impact\n\nAny application using `UAuthForm` (or `UForm` with credential-shaped fields) as documented. The cleartext password lands in:\n\n- the address bar,\n- `window.history`,\n- the `Referer` header of every same-origin subresource fetched from the resulting URL,\n- access logs of any reverse proxy, CDN, or WAF that records request URLs.\n\n### Patch\n\nDefault the rendered `\u003cform\u003e` to `method=\"post\"` so the pre-hydration fallback submits as POST rather than GET. Vue's `@submit.prevent` still intercepts the hydrated case; the attribute only matters in the race window. Applications that explicitly want native GET submission can opt back in by passing `method=\"get\"`.\n\n### Credit\n\nReported by @nimonian. Originally filed as `GHSA-92g7-2fpq-hmq8` against `nuxt/nuxt`; moved here because the affected code lives in `@nuxt/ui`.","modified":"2026-08-04T22:00:24.148635461Z","published":"2026-07-02T20:16:12Z","database_specific":{"cwe_ids":["CWE-200","CWE-598"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T20:16:12Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nuxt/ui/security/advisories/GHSA-gj2h-2fpw-fhv9"},{"type":"WEB","url":"https://github.com/nuxt/ui/pull/6512"},{"type":"PACKAGE","url":"https://github.com/nuxt/ui"},{"type":"WEB","url":"https://github.com/nuxt/ui/releases/tag/v4.8.1"}],"affected":[{"package":{"name":"@nuxt/ui","ecosystem":"npm","purl":"pkg:npm/%40nuxt/ui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-gj2h-2fpw-fhv9/GHSA-gj2h-2fpw-fhv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}