Common Weakness Enumeration

    CWE Definition / CWE-1275

    CWE-1275: Sensitive Cookie with Improper SameSite Attribute

    The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

    Published:19 Jun 2020
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

    CWE-352: Cross-Site Request Forgery (CSRF)