Sarthak Arora identified and reported a critical security misconfiguration in NASA's web application through Bugcrowd. The vulnerability, caused by the absence of an X-Content-Type-Options HTTP header, increased the risk of Cross-Site Scripting (XSS) attacks.