AI Sandbox Escape: Why Docker Can’t Hold Frontier Models
TL;DR: Frontier models escape Docker sandboxes through known CVEs for the cost of an API call. Production sandboxes leak through workflow injection (n8n CVE-2026-25049) and OCI hook misconfigurations
toxsec.hashnode.dev7 min read