CVE-2024-55215: Jrohy Trojan

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

Affected products

  • Jrohy Trojan: from 2.0.0, up to and including 2.15.3

Published 2025-02-07. Last modified 2026-06-17.