legit issue for local installs but this is why we run the hosted platform in gVisor. even with the exploit you're trapped in a sandbox with no access to the host node. we treat every container as hostile by default.
So... what use is an agent that cannot reach out of its trap?
that response is not comforting
You sound like the confident techie character in a Michael Crichton novel pronouncing "We've thought of everything there's no way for the demon to escape" shortly before the demon escapes.