Junglewise Threat Intelligence

Nuxt @nuxt/ui credential leak via GET in UForm and UAuthForm

Severity: medium · CVSS 6.9 · Published 2026-07-02

Vendors: Nuxt, npm.

Executive brief

A vulnerability in the Nuxt UI library could cause sensitive information, such as user passwords, to be exposed in web browser history and server logs. This occurs when a user submits a login or data form before the website has fully finished loading its interactive components. In these cases, the browser may transmit the form data as part of the web address (URL) instead of a secure background request, making the credentials visible to anyone with access to the network traffic or browser history.

Technical details

The UForm and UAuthForm components in @nuxt/ui render server-side HTML <form> elements without explicit 'method' or 'action' attributes. The library relies on Vue's @submit.prevent handler to intercept submissions, but this handler is only active after client-side hydration. If a user triggers a submission (e.g., via autofill and Enter) on a slow network or if JavaScript fails to load, the browser defaults to a native GET request. This serializes all form fields, including sensitive password inputs, into the URL query string, exposing them to browser history, Referer headers, and web server access logs. The recommended fix is to default the rendered markup to method='post'.

Affected products

  • Nuxt @nuxt/ui <= 4.7.1

Timeline

  • 2026-05-29: disclosed: Originally reported against nuxt/nuxt; later moved to nuxt/ui.
  • 2026-07-02: advisory

References

Related threats