mediumVulnerability

GHSA-gj2h-2fpw-fhv9

### Summary `UForm` and `UAuthForm` render a server-side `<form>` element with no `method` and no `action` attribute, relying on a hydrated `@submit.prevent` handler to intercept submission. If a user submits the form before Vue hydration has attached the handler (autofill plus Enter on a slow network, JS bundle blocked by CSP or CDN failure, etc.), the browser performs the native default: a `GET` to the current URL with every named field, including `<input type="password">`, serialised into the query string. ### Details `src/runtime/components/Form.vue` (around the template's `<form>` element) emits: ```vue <component :is="parentBus ? 'div' : 'form'" :id="formId" ref="formRef" :class="ui({ class: [uiProp?.base, props.class] })" @submit.prevent="onSubmitWrapper" > ``` No `method`, no `action`. `@submit.prevent` is the only thing stopping native submission, and it only exists after hydration. `UAuthForm` composes `UForm` and inherits the same shape. The SSR snapshot of `UAuthForm` (`test/components/__snapshots__/AuthForm.spec.ts.snap`) shows the rendered markup, with `<input type="password" name="password">` inside a `<form>` that has no `method`. ### Proof of concept Reported by @nimonian: 1. Create a minimal Nuxt app with a `UAuthForm`. 2. Build for production and visit in a browser with network throttling at 4G or slower. 3. Enter credentials. 4. Submit (or let autofill + Enter fire before hydration). The URL becomes `/login?email=…&password=…`. Reproducible deterministically in Playwright by triggering submit immediately on `load`. ### Impact Any application using `UAuthForm` (or `UForm` with credential-shaped fields) as documented. The cleartext password lands in: - the address bar, - `window.history`, - the `Referer` header of every same-origin subresource fetched from the resulting URL, - access logs of any reverse proxy, CDN, or WAF that records request URLs. ### Patch Default the rendered `<form>` to `method="post"` so the pre-hydrat

Properties

ghsa_id
GHSA-gj2h-2fpw-fhv9
severity
medium
summary
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
cve_id
GHSA-gj2h-2fpw-fhv9
is_ghsa_only
true
ghsa_published
2026-07-02T20:16:12Z
source_url
https://github.com/advisories/GHSA-gj2h-2fpw-fhv9
ghsa_updated
2026-07-02T20:16:13Z

Related Entities (5)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@nuxt/ui

AFFECTS (1)

[Software]npm/@nuxt/ui

HAS_WEAKNESS (2)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
[Weakness]Use of GET Request Method With Sensitive Query Strings

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-gj2h-2fpw-fhv9 — Ninja Signal Threat Intelligence | Ninja Signal