LXC security can doubtless be mis-configured; how much info can you share regarding your setup? From a few minutes research it sounds like you need user namespaces and seccomp for starters.
Redhat|OpenStack relies on SELinux much more than seccomp: https://news.ycombinator.com/item?id=14220503 http://rhelblog.redhat.com/2017/01/13/selinux-mitigates-cont...
Abusing Privileged and Unprivileged Linux Containers (2016) | https://www.nccgroup.trust/globalassets/our-research/us/whit...
You should get some free testing from your Show HN! https://news.ycombinator.com/item?id=14245447