ATLAS Landscape
AML.T0105

Escape to Host

Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment. There are many ways an adversary may escape from a container or sandbox environment via AI Systems. For example, modifying an AI Agent's configuration to disable safety features or user confirmations could allow the adversary to invoke tools to be run on host environments rather than in the sandbox.

Severity CVE CVSS
CRITICAL CVE-2026-39888 10.0
CRITICAL CVE-2026-34938 10.0
CRITICAL CVE-2025-5120 10.0
CRITICAL CVE-2026-27494 9.9
CRITICAL CVE-2026-0863 9.9
CRITICAL CVE-2026-27577 9.9
CRITICAL CVE-2026-27495 9.9
CRITICAL CVE-2026-25115 9.9
CRITICAL CVE-2026-25049 9.9
CRITICAL CVE-2026-1470 9.9
CRITICAL CVE-2025-68668 9.9
CRITICAL CVE-2026-21877 9.9
CRITICAL CVE-2026-33309 9.9
CRITICAL CVE-2026-25592 9.9
CRITICAL CVE-2026-27966 9.8
CRITICAL CVE-2024-42835 9.8
CRITICAL CVE-2026-2654 9.8
CRITICAL CVE-2026-41268 9.8
CRITICAL CVE-2024-48061 9.8
CRITICAL CVE-2025-15036 9.6
CRITICAL CVE-2026-35216 9.1
CRITICAL CVE-2025-15031 9.1
CRITICAL CVE-2026-44007 9.1
CRITICAL CVE-2026-27493 9.0
HIGH CVE-2025-68613 8.8
HIGH CVE-2026-35044 8.8
HIGH CVE-2026-34955 8.8
HIGH CVE-2026-40158 8.6
HIGH CVE-2024-6982 8.4
HIGH CVE-2026-2033 8.1
HIGH CVE-2024-8060 8.1
HIGH CVE-2026-27905 7.8
HIGH GHSA-hr5v-j9h9-xjhg 7.7
HIGH GHSA-cvrr-qhgw-2mm6 7.7
HIGH CVE-2025-14287 7.5
MEDIUM GHSA-gpx9-96j6-pp87 6.5
MEDIUM CVE-2026-4963 6.3
MEDIUM CVE-2025-12695 5.9
MEDIUM CVE-2025-8917 5.8
MEDIUM CVE-2025-61914 5.4
MEDIUM CVE-2025-68697 5.4
MEDIUM CVE-2025-3000 5.3
MEDIUM CVE-2026-34452
UNKNOWN CVE-2025-66479
MEDIUM GHSA-42mx-vp8m-j7qh
HIGH CVE-2026-0770
HIGH GHSA-7437-7hg8-frrw
MEDIUM GHSA-w9j9-w4cp-6wgr
UNKNOWN CVE-2026-0771
CRITICAL GHSA-v38x-c887-992f
CRITICAL GHSA-9wc7-mj3f-74xv
UNKNOWN CVE-2026-2275
MEDIUM GHSA-5h3g-6xhh-rg6p
HIGH GHSA-wppj-c6mr-83jj
UNKNOWN CVE-2026-42234
UNKNOWN CVE-2026-2287
HIGH CVE-2026-39861
UNKNOWN CVE-2025-59532