A race while mounting volumes allows a possible symlink-exchange attack, allowing a user whom can start multiple containers with custom volume mount configurations to escape the container.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0087" }