
CRI-O sandbox bookkeeping can be overwritten. Restart, then the recreate escapes!! CVE-2026-62146 (CVSS 7.8): Attacker-influenced pod metadata lands in CRI-O's reserved sandbox state. After reload it is trusted. Next container recreate exposes a host runtime resource inside the pod. Updated 30 Sep. Public repro is up!! https://github.com/TeamN4C/SG-2026-0026 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #CloudSecurity #ContainerEscape #Kubernetes
