CVE-2016-1239

duck before 0.10 did not properly handle loading of untrusted code from the current directory..