Container Escape via Insecure WORKDIR Handling in Docker/Buildkit Affects GPU-based ML Workloads | AI Breaking Wire