diff --git a/mdx/_rules/check_mdui.xsl b/mdx/_rules/check_mdui.xsl index 15194acd..6c4b3dd9 100644 --- a/mdx/_rules/check_mdui.xsl +++ b/mdx/_rules/check_mdui.xsl @@ -176,7 +176,10 @@ This is a SHOULD in the specification; we treat it as a MUST here. - Exception: allow data: URIs as well. + Exception: allow data: URIs as well. The spec is currently + ambiguous about this, clarification ticket is here: + + https://tools.oasis-open.org/issues/browse/SECURITY-24 -->