1. Trivial Container Breakout: Access to ``docker.sock`` allows any process inside the container to communicate with the host Docker daemon. An attacker submitting a malicious pull request or tainted dependency simply executes: ``docker run -v /:/host -it alpine chroot /host`` In under 2 seconds, the attacker escapes the container, obtaining full root access on the host operating system. 2. Cloud IAM Instance Metadata Theft: Once on the host, the attacker queries the cloud instance metadata service (IMDS at ``169.254.169.254``). They extract temporary IAM session tokens associated with the runner's cloud instance role. If the runner instance has permissions to manage S3, push to ECR, or touch Kubernetes clusters, your entire cloud organization is compromised. 3. Persistent Pipeline Backdoors: Attackers can silently install rootkits, modify adjacent container volumes, or poison production build artifacts before they are deployed.