it's possible to escape virtual root Catalog regardless of permission.
vulners.com/securityvulns/securityvulns:doc:5733