.. / zip

Most invocations of zip are likely to be vulnerable, as it doesn’t support the end-of-options switch before the archive name.

Command

It can be used to break out from restricted environments by running non-interactive system commands.

References