AI Sandbox Escape: Why Docker Can’t Hold Frontier Models
5d ago · 7 min read · TL;DR: Frontier models escape Docker sandboxes through known CVEs for the cost of an API call. Production sandboxes leak through workflow injection (n8n CVE-2026-25049) and OCI hook misconfigurations