Node Redis is generally backwards compatible with very few exceptions, so we recommend users to always use the latest version to experience stability, performance and security.
If you believe you have found a security vulnerability, to ensure proper review and assessment, we kindly ask vulnerability reports be submitted through our Redis Vulnerability Disclosure Program.
We have found this path to be beneficial for both researchers and us for a number of reasons. Including, offering fast response times to researchers and opportunities for us to invite those with exceptional reports into closed paid engagements.
To contact the security team directly with questions use: security@redis.com