patriksimek/vm2

v3.10.0 introduced a breaking change

Open

#543 aberto em 4 de nov. de 2025

Ver no GitHub
 (1 comment) (0 reactions) (0 assignees)JavaScript (285 forks)batch import
bugconfirmedhelp wanted

Métricas do repositório

Stars
 (3.798 stars)
Métricas de merge de PR
 (Nenhuma PRs mesclada em 30d)

Description

With our use case we use webpack to bundle code into a single script. This happens with any package that uses inherits or the nodejs util.inherits.

With https://github.com/patriksimek/vm2/pull/540 this broke usage of these packages and it will result in this line throwing https://github.com/patriksimek/vm2/blob/main/lib/setup-sandbox.js#L561.

I am unsure if this change is for security reasons as the PR doesn't go into details.

Here is a minimal script to reproduce the error:

const script = `
const util = require('util');
const EventEmitter = require('events');

function MyStream() {
  console.log("This is sha1");
}

util.inherits(MyStream, EventEmitter);
`;

const vmScript = new VMScript(script);
const vm = new NodeVM({
console: 'inherit',
require: {
  builtin: ['util', 'events'],
},
});
vm.run(vmScript);

Guia do colaborador