The code is pretty straightforward and not that large. I feel like the only possibility of such an exploit would probably be through Docker itself - or some sort of cross site scripting.
What is one of your package dependencies dependencies have an exploit?
Overall, nice idea and demo. I’d be a bit hesitant to run, but creative implementation