Common Weakness Enumeration

    CWE Definition / CWE-540

    CWE-540: Inclusion of Sensitive Information in Source Code

    Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory

    CWE-540: Inclusion of Sensitive Information in Source Code | CVE-DB