If you are concerned about security and you want to run kodi then it might be best to think about running it on a completely separate system.
Why? There are numerous issues in media decoders and kodi bundles an outdated ffmpeg version which might have various security issues. In addition to that media decoders like h264 and hevc run in kernel space and are likely to contain security relevant bugs, too. In that case a container won't help you much if you find a way to trigger a kernel bug via some (streamed) media file.
As RPiOS is a bit slow with kernel updates it's also not the best choice if you are concerned about kernel security problems - distros following mainline kernel (eg Debian) will be a lot faster shipping security patches - but of course they won't contain the not-upstreamed media codecs so are not a good choice for Kodi on RPi.
LibreELEC will be even worse as kernel updates are shipped as part of the system and can't be upgraded - and LE10 uses kernel 5.10 which is now on bare life support from RPi.
And, there may be another practical argument for running RPi with kodi on a dedicated system: performance. RPi4 is pretty much at the limit with H264 1080p60 and HEVC 4kp50/60 decoding and output - containers running in the background might ruin your movie evening.
so long,
Hias