Putting aside the WASM sandboxing (I’m not familiar enough with it to understand how sandboxing works) there’s a DoS vector at least. Even regexes have had many DoS issues, and I can’t imagine WASM being easier to sandbox for DoS risk.
There exist Wasm interpreters capable of limiting the number of instructions executed.
There exist Wasm interpreters capable of limiting the number of instructions executed.