yes, but if your adversary is capable of exploiting a one-way diode to RCE, you might as well just give up.
there are a lot of such extremely hypothetical attacks no one should take seriously. you might as well worry about sensitive data being exfiltrated from your unshielded optical nerve,
So there's still an attack surface, but it's a lot smaller. Any side channel exploit would need to work (at least in some initial form) without changes to the software on the isolated side, since you otherwise can't bootstrap your way to installing it.