Imagine if wikipedia was a native app, what this vuln would have caused. I for one prefer using stuff in the browser where at least it's sandboxed. Also, there's nothing stopping you from disabling JS in your browser.
Wikipedia should be straight hypermedia. Simple.
If it was a native app it wouldn't be grabbing one of the hosted files and running it as code.