I recently added the API library to my project and received a NPM vulnerability report. It's coming from the Axios dependency pointing to a version that exposes CSRF tokens. Here is the GitHub report on the issue.
If you'd like, I would happy to post a PR to update the dependency.