Sounds the same as xp_cmdshell scenarios in past. Although worth pointing out Microsoft there did lock down things further to even disable the feature and it has to be turned on explicitly. That's possibly an improvement Postgress can do to avoid easy pivoting. Its what a less defensive security reply would include, because if hackers use it to pivot it might not look good down the road. But from a pure argument stan…
If you take that to its logical conclusion you end up with completely unusable, user-hostile software that becomes nearly useless.
The fact that everything can be abused, should not be a reason to ban everything either.