TIL Nashorn is a JavaScript VM written in Java and gives direct access to Java classes. There's even a reverse shell payload for it, which has apparently been improved/fixed by this chap @mosesrenegade who's on here.
https://gist.github.com/mosesrenegade/dd565dba9360a84b3c2d6e44b8381dbd
#reverseshells #nashorn #payloads