It looks like they bind the Docker socket into the guest controller[1], but maybe not the guest itself. But yeah: unrestricted container root plus any capabilities means that they're only one low-effort bug away from a container escape.
[1]: https://github.com/hackerschoice/segfault/blob/main/docker-c...