According to this article you run some security risks when you open up an X socket, but you reduce the risks massively by not running --privileged.

Some extra info here about not running a container as root

This is maybe a bit late for you but hopefully will help anyone else who finds this working but insecure answer.