Agreed, adding to this, if a malicious actor already has the ability to execute arbitrary LUA scripts on your redis instance, then you are probably already pretty screwed.
I've reread my comment and the parent comment, and I don't understand how this is not clear?