Additional Information
Vulnerability CVE-2021-32798 affects SystemLink Server 2023 Q1 and later versions, because they all ship JupyterHub version 6.0.3.
Originally, CVE-2021-32798 listed the affected jupyter versions as: 5.7.0 <= jupyter < 5.7.11. This did not affect modern SystemLink Server versions.
On June 16, 2026, CVE-2021-32798 added affected versions to include: 6.0.0 <= jupyter < 6.4.1.
SystemLink Server has shipped with Jupyter version 6.0.3 since SystemLink Server 2023 Q1.
The core of vulnerability CVE-2021-32798 is that Jupyter notebooks executing with sufficient privileges can change important files in Windows folders (on the SystemLink Server computer). Any SystemLink Server versions prior to 2026 Q3 executed Jupyter notebooks with administrative permissions.