Containers have a history of escape vulnerabilities, for reasons like sharing a kernel with the host and other containers.
VMs are designed from the ground up to isolate guests, rather than focusing on application deployment.
Firecracker is the modern container alternative in untrusted compute scenarios, with Fly.io even converting container images into Firecracker VMs.