More complexity leading to bigger surface area for potential attacks, yes. GPU and file access, yes. But nothing to do with turing completeness.
Here's a non turing complete language I wouldn't like to be able to run in a web context. It has a single command: rm {path}
On the other hand a turing complete language that has no access to any IO, DOM manipulation etc. I would be perfectly happy to let run.
It isn't the power that comes from turing completeness that makes javascript a potential security vulnerability, it's the interactions it can have outside of computation.