Can you explain why this is not ? Code injection in production environments is generally considered an easy attack vector. Lots of CVE's around this in other language SDK's that have been ironed out over the last decade and half. I don't think Common Lisp gets "special protection" here or does it ?
Unless you are restricting this to only development in which case there are a lot more languages other than common lisp that support hot-reloading/re-definition.