You can’t express anything malicious in JavaScript either, yet vulnerabilities are constantly found in web browsers, including WebAssembly JITs.
You can express malicious things in Go, yet the number of RCEs in Go apps is pretty much zero.
You can express malicious things in Go, yet the number of RCEs in Go apps is pretty much zero.
You have to be more specific because lots of fraud is possible by misleading the user through JavaScript tricks.